SSH bastions vs zero-trust access: when each one wins
⏱️ 1 min read
What each one actually is
A bastion host is a single SSH-reachable jump box; everything else sits on a private network. Zero-trust (NordLayer, Tailscale, Cloudflare Access) puts an identity check on every connection — no exposed ports anywhere, no shared jump box to harden.
Where the bastion wins
- Cost: one small VM, no per-seat licensing.
- Simplicity: the whole company already knows
ssh; nothing new to learn. - Fewer moving parts: no agent on servers, no controller to patch.
Where zero-trust wins
- Blast radius: a leaked bastion key reaches everything; a leaked zero-trust identity hits MFA and device posture on the next hop.
- Auditability: every access is an identity event, not an anonymous port-22 session.
- No open internet surface: there is no port 22 to scan, ever.
The honest recommendation
Under ~5 servers and one admin: a hardened bastion is fine and free. The moment you add contractors, multiple clouds, or compliance questions, identity-based access pays for itself: NordLayer covers per-device access with posture checks. (Partner link.) Whatever you pick: keys not passwords, MFA on the control plane, and keep one break-glass console path so the fix for a broken policy is never "restore the whole VM".