如何通过Bastion Host访问AWS VPC私有子网内运行的Web应用?
Nice setup you've got with Terraform! Let's walk through exactly how to access your private subnet web app using that Bastion Host—there are a few straightforward methods depending on what you need to do.
前置条件(Must-Haves First)
Before diving in, make sure these security group rules are in place (you probably already set these via Terraform, but double-check):
- Bastion Host Security Group: Allow inbound SSH (port 22) only from your trusted local IP/VPN IP (never open to
0.0.0.0/0—that's a huge risk). - Private Web App Instance Security Group: Allow inbound SSH (port 22) from the Bastion Host's security group. If you're accessing the web UI directly via port forwarding, also allow inbound traffic on your web port (80/443) from the Bastion Host's security group.
方法1:直接SSH到私有Web实例(ProxyJump,现代SSH首选)
Modern SSH clients (OpenSSH 7.3+) support the ProxyJump flag, which lets you jump straight to the private instance without manually logging into the Bastion first.
单次命令
# Replace placeholders with your actual values ssh -i /path/to/your-aws-key.pem -J ec2-user@<BASTION_PUBLIC_IP> ec2-user@<PRIVATE_WEB_APP_PRIVATE_IP>
简化配置(~/.ssh/config)
To avoid typing the full command every time, add this to your local ~/.ssh/config:
Host bastion HostName <BASTION_PUBLIC_IP> User ec2-user # Or your AMI's default user (e.g., ubuntu for Ubuntu AMIs) IdentityFile /path/to/your-aws-key.pem Host private-web-app HostName <PRIVATE_WEB_APP_PRIVATE_IP> User ec2-user IdentityFile /path/to/your-aws-key.pem ProxyJump bastion
Now you can just run:
ssh private-web-app
方法2:本地端口转发(访问Web应用的UI)
If you need to access the web app's frontend (e.g., a dashboard on port 80 or 443), use local port forwarding to tunnel traffic through the Bastion Host to the private instance.
转发HTTP(端口80)
ssh -i /path/to/your-aws-key.pem -L 8080:<PRIVATE_WEB_APP_PRIVATE_IP>:80 ec2-user@<BASTION_PUBLIC_IP>
Once the tunnel is active, open your local browser and go to http://localhost:8080—you'll be accessing the private web app directly.
转发HTTPS(端口443)
ssh -i /path/to/your-aws-key.pem -L 8443:<PRIVATE_WEB_APP_PRIVATE_IP>:443 ec2-user@<BASTION_PUBLIC_IP>
Then visit https://localhost:8443 locally.
Tip: Keep the SSH session open while you need access—closing it will drop the tunnel.
方法3:SSH Agent Forwarding(安全跳转,无密钥在堡垒机)
If you don't want to copy your private key to the Bastion Host (which is a bad security practice), use SSH Agent Forwarding to pass your local key to the Bastion temporarily.
- Start your local SSH agent:
eval $(ssh-agent) - Add your AWS private key to the agent:
ssh-add /path/to/your-aws-key.pem - Log into the Bastion with agent forwarding enabled (
-Aflag):ssh -A ec2-user@<BASTION_PUBLIC_IP> - From the Bastion, SSH directly to the private web app (no key needed here—your local agent handles authentication):
ssh ec2-user@<PRIVATE_WEB_APP_PRIVATE_IP>
关键安全注意事项
- Lock down Bastion access: Never allow SSH from
0.0.0.0/0—restrict it to only your trusted IPs via security groups. - Disable password authentication: Ensure both the Bastion and private instances only allow key-based SSH login (set
PasswordAuthentication noin/etc/ssh/sshd_config). - Rotate keys regularly: Don't use the same key forever—rotate your AWS SSH keys periodically.
- Optional: Use AWS Session Manager: For even better security, you can configure the Bastion to use AWS Systems Manager Session Manager instead of exposing a public IP. This lets you access the Bastion via the AWS Console or CLI without opening port 22 to the internet.
内容的提问来源于stack exchange,提问作者Basith

