You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何通过Bastion Host访问AWS VPC私有子网内运行的Web应用?

Nice setup you've got with Terraform! Let's walk through exactly how to access your private subnet web app using that Bastion Host—there are a few straightforward methods depending on what you need to do.


前置条件(Must-Haves First)

Before diving in, make sure these security group rules are in place (you probably already set these via Terraform, but double-check):

  • Bastion Host Security Group: Allow inbound SSH (port 22) only from your trusted local IP/VPN IP (never open to 0.0.0.0/0—that's a huge risk).
  • Private Web App Instance Security Group: Allow inbound SSH (port 22) from the Bastion Host's security group. If you're accessing the web UI directly via port forwarding, also allow inbound traffic on your web port (80/443) from the Bastion Host's security group.

方法1:直接SSH到私有Web实例(ProxyJump,现代SSH首选)

Modern SSH clients (OpenSSH 7.3+) support the ProxyJump flag, which lets you jump straight to the private instance without manually logging into the Bastion first.

单次命令

# Replace placeholders with your actual values
ssh -i /path/to/your-aws-key.pem -J ec2-user@<BASTION_PUBLIC_IP> ec2-user@<PRIVATE_WEB_APP_PRIVATE_IP>

简化配置(~/.ssh/config)

To avoid typing the full command every time, add this to your local ~/.ssh/config:

Host bastion
  HostName <BASTION_PUBLIC_IP>
  User ec2-user  # Or your AMI's default user (e.g., ubuntu for Ubuntu AMIs)
  IdentityFile /path/to/your-aws-key.pem

Host private-web-app
  HostName <PRIVATE_WEB_APP_PRIVATE_IP>
  User ec2-user
  IdentityFile /path/to/your-aws-key.pem
  ProxyJump bastion

Now you can just run:

ssh private-web-app

方法2:本地端口转发(访问Web应用的UI)

If you need to access the web app's frontend (e.g., a dashboard on port 80 or 443), use local port forwarding to tunnel traffic through the Bastion Host to the private instance.

转发HTTP(端口80)

ssh -i /path/to/your-aws-key.pem -L 8080:<PRIVATE_WEB_APP_PRIVATE_IP>:80 ec2-user@<BASTION_PUBLIC_IP>

Once the tunnel is active, open your local browser and go to http://localhost:8080—you'll be accessing the private web app directly.

转发HTTPS(端口443)

ssh -i /path/to/your-aws-key.pem -L 8443:<PRIVATE_WEB_APP_PRIVATE_IP>:443 ec2-user@<BASTION_PUBLIC_IP>

Then visit https://localhost:8443 locally.

Tip: Keep the SSH session open while you need access—closing it will drop the tunnel.


方法3:SSH Agent Forwarding(安全跳转,无密钥在堡垒机)

If you don't want to copy your private key to the Bastion Host (which is a bad security practice), use SSH Agent Forwarding to pass your local key to the Bastion temporarily.

  1. Start your local SSH agent:
    eval $(ssh-agent)
    
  2. Add your AWS private key to the agent:
    ssh-add /path/to/your-aws-key.pem
    
  3. Log into the Bastion with agent forwarding enabled (-A flag):
    ssh -A ec2-user@<BASTION_PUBLIC_IP>
    
  4. From the Bastion, SSH directly to the private web app (no key needed here—your local agent handles authentication):
    ssh ec2-user@<PRIVATE_WEB_APP_PRIVATE_IP>
    

关键安全注意事项

  • Lock down Bastion access: Never allow SSH from 0.0.0.0/0—restrict it to only your trusted IPs via security groups.
  • Disable password authentication: Ensure both the Bastion and private instances only allow key-based SSH login (set PasswordAuthentication no in /etc/ssh/sshd_config).
  • Rotate keys regularly: Don't use the same key forever—rotate your AWS SSH keys periodically.
  • Optional: Use AWS Session Manager: For even better security, you can configure the Bastion to use AWS Systems Manager Session Manager instead of exposing a public IP. This lets you access the Bastion via the AWS Console or CLI without opening port 22 to the internet.

内容的提问来源于stack exchange,提问作者Basith

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.19 04:30:56