Currently the option to create a security group rule only allows RemoteGroupID or RemoteIPPrefix on rule creation, could this be extended to allow the use of remote address groups per the API?
https://docs.openstack.org/api-ref/network/v2/index.html#address-groups