Bastion instances
To follow best security practices, we need to secure our vulnerable instances, such as backend app servers, and databases in private subnets. In a previous section, we mentioned that NAT instances, or an NAT gateway, can be used to give our private instances access to the internet, to download security patches, or to access public AWS services. However, our server administrators will need to be able to connect with our private instances, in order to perform upgrades or security updates. Since there is no direct route to the instances from the internet, we need to launch a Bastion instance, in a public subnet. The administrators can connect to this instance, and from there are able to log in to the private instances. The ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access