The AWS CLI SG commands are not necessary, kops creates an SG with these ports open to the correct SG by default