Part 13 · CI/CD, Git & Cloud

Jump server, bastion host và zero-standing access

Jump host là điểm trung chuyển quản trị vào private network. Nó giảm public exposure nhưng đồng thời trở thành privileged choke point cần hardening, audit và HA.

1. Khái niệm

Jump server/host là máy trung gian mà operator đăng nhập trước rồi truy cập targets nội bộ. Bastion host nhấn mạnh host được hardened ở network edge; thực tế hai thuật ngữ thường dùng thay nhau. Nó khác application reverse proxy: bastion phục vụ administrative protocols như SSH/RDP, không route user application traffic.

Admin device → IdP/VPN/ZTNA → Bastion/session service → private VM/DB
                    audit/control         no public IP

2. Lợi ích và giới hạn

3. Thiết kế network

Chỉ cho inbound từ corporate VPN/ZTNA/approved CIDR hoặc managed access plane; targets chỉ nhận admin port từ bastion security identity/group, không từ toàn subnet. Egress bastion được allow-list theo management needs. Không dùng bastion làm NAT/proxy chung hoặc lưu data/app secrets.

4. Identity và credentials

5. Hardening và operations

Bastion là phương án, không phải mặc định tốt nhất: managed session services như AWS Systems Manager Session Manager, Azure Bastion hoặc zero-trust access proxy có thể loại inbound SSH/RDP, giảm key distribution và cải thiện audit. Vẫn phải threat-model provider/control-plane dependency.

6. SSH ProxyJump example

Host bastion
  HostName bastion.example.com
  User admin
  IdentityFile ~/.ssh/id_ed25519

Host app-private
  HostName 10.20.1.15
  User appops
  ProxyJump bastion

Configuration tiện lợi không thay policy. Host key verification phải bật; không dùng StrictHostKeyChecking=no. Private key không được copy lên bastion.

7. Break-glass

Emergency access có credential/role tách biệt, MFA, approval hoặc sealed procedure, alert ngay khi dùng, expiry/rotation sau incident và post-use review. Break-glass không phụ thuộc cùng IdP/network path mà nó dùng để cứu, nhưng phải được bảo vệ và diễn tập.

8. Câu trả lời phỏng vấn ngắn

Em dùng bastion khi private resources vẫn cần administrative SSH/RDP nhưng không muốn expose từng máy ra Internet. Bastion chỉ nhận traffic từ trusted access path, dùng per-user MFA/short-lived credentials, targets chỉ allow từ bastion identity, và mọi session được audit. Em cũng đánh giá managed session service/ZTNA vì bastion tự quản là high-value target và single point of access.

9. Checklist

Tài liệu: AWS Session Manager · Azure Bastion · OpenSSH ProxyJump