Bamboo OnDemand must run in a separate region from our EC2 instances because of license restrictions ("Maximum Number Of Elastic Instances" cannot be greater than 1 in the Configuration section). EC2 Security Groups will only allow in-Region security groups to be identified. Because of this I cannot figure out how to allow elastic bamboo instances access our EC2 instances with security integrity. These are non-VPC instances.
For example... How can I use SSH/SCP tasks without opening port 22 on my EC2 instances up to the world?