What is Bastion Host?
A bastion host is a hardened system that provides controlled administrative access to a more protected network or resource. It is often a jump host for SSH or RDP. A bastion host is not the same as a load balancer, and it does not by itself authorize each downstream request. Limit its services, require strong authentication, record administrative activity, and keep its privileges narrow.
Why it matters
A bastion host can reduce the number of administrative services exposed to a wider network. It also concentrates privileged access in one place that needs strict control and monitoring.
How it works
- Administrators harden the bastion and expose only the required management services.
- An administrator authenticates to the bastion under a narrow access policy.
- The bastion opens the approved downstream connection and records the administrative activity.
Example
An engineer connects by SSH to a hardened jump host. From that host, the engineer opens an SSH session to one private database server with a separate restricted credential.
Pomerium boundary
Pomerium can protect SSH with native SSH access or a TCP tunnel, and it can protect RDP with TCP and UDP routes through Pomerium CLI or Pomerium Desktop. These paths can give users access to a named service without broad private-network reach. They are not the same as operating a bastion host.
Limits and non-claims
- A compromised bastion can expose every resource and credential that it can reach.
- A shared downstream credential can hide the identity of the original administrator.
- The bastion does not authorize individual actions inside a downstream service unless that service also enforces them.
Evaluation checklist
- Which administrator identities, credentials, targets, and actions must pass through the bastion?
- Can direct network reachability, shared credentials, or emergency access bypass it?
- Do session evidence, command authorization, containment, and recovery cover a bastion compromise?
