Chef-provisioning - AWS security group rules - Mix!?

Hi All

Can anyone help me with referencing lazy and “non-lazy” inbound rules for a security group. It seems to want one, or the other. Not both.

  solr_sg = aws_security_group 'solr-vpc' do
    vpc lazy { }
    inbound_rules ''                => [ 22, 80, 1099, 3000, 8983..8990 ]
                  lazy  {         
                          {    => [ 8983..8990 ]}
                          {    => [ 443 ]}

Currently, the ports for get opened, but not the lazy ones. Can a mix of lazy, and non lazy be done?

Many thanks