You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
There's not actual definition of a Bastion host. However, this is (at least) a server in a DMZ. One of the functions could be a "jump box" which typically accepts SSH connections.
There are many reasons that the Bastion host might have a role associated to it. One of them may be to add authorised public keys using IAM .
Another might be to trigger an SNS/SES notification for OSSEC alerts.
Probably one of the most important would be to allow SSM to run automation against this host (updates, patches, config, audits, etc). However, this might not be your preferred method.
Regardless, you get the point.
For smaller companies/startups, the Bastion might even double as a lightweight scheduler that executes tasks and uploads results/files to S3. There may be many uses for the Bastion in these contexts and will ultimately come down to compromise (It Depends™)
Thanks for sharing great templates! I could get a good amount of knowledge of AWS architecture through these.
Thanks!
-- J
Request
Details
The text was updated successfully, but these errors were encountered: