← Back to all posts

SSH bastions vs zero-trust access: when each one wins

Published October 1, 2026

⏱️ 1 min read

What each one actually is

A bastion host is a single SSH-reachable jump box; everything else sits on a private network. Zero-trust (NordLayer, Tailscale, Cloudflare Access) puts an identity check on every connection — no exposed ports anywhere, no shared jump box to harden.

Where the bastion wins

  1. Cost: one small VM, no per-seat licensing.
  2. Simplicity: the whole company already knows ssh; nothing new to learn.
  3. Fewer moving parts: no agent on servers, no controller to patch.

Where zero-trust wins

  1. Blast radius: a leaked bastion key reaches everything; a leaked zero-trust identity hits MFA and device posture on the next hop.
  2. Auditability: every access is an identity event, not an anonymous port-22 session.
  3. No open internet surface: there is no port 22 to scan, ever.

The honest recommendation

Under ~5 servers and one admin: a hardened bastion is fine and free. The moment you add contractors, multiple clouds, or compliance questions, identity-based access pays for itself: NordLayer covers per-device access with posture checks. (Partner link.) Whatever you pick: keys not passwords, MFA on the control plane, and keep one break-glass console path so the fix for a broken policy is never "restore the whole VM".

Partner pick — sponsored

NordLayer — our security pick for this stack

Zero-trust access and device security for your whole team — covers the hardening steps above.

Get NordLayer →
Also vetted

Sentry — Catch the error behind this class of bug — exact line, stack and user context.

Get Sentry →

We earn a commission if you buy through our links — it never costs you extra. More vetted tools on our picks hub · comparing clouds? DigitalOcean vs Vultr and vs AWS · full deals: DigitalOcean · Vultr · NordLayer · Semrush

#AmazonAssociate — As an Amazon Associate I earn from qualifying purchases. Full disclosure →