Q: Your infrastructure team maintains 12 public Linux jump-box VMs to allow engineers to troubleshoot internal databases and private VMs. Attackers constantly scan and brute-force port 22 on these public IPs. How do you replace all jump boxes with Azure Bastion, configure native SSH tunneling via Azure CLI, and grant time-limited access without Azure Portal permissions?
Runbook for eliminating exposed public jump-box VMs by deploying Azure Bastion Developer / Standard tier, tunneling SSH/RDP via Azure CLI, and provisioning Bastion Shareable Links.
Want to master this scenario in a live sandbox? Stephane Maarek's AWS Certified DevOps Engineer Professional Masterclass on Udemy covers this exact problem with hands-on terminal drills.
🛠️ Production Runbook & Step-by-Step Resolution
Provision AzureBastionSubnet & Deploy Azure Bastion Standard
Create the dedicated management subnet and provision Bastion gateway:
- Subnet Creation: Allocated dedicated subnet
AzureBastionSubnet(/26 prefix) in the hub VNet:az network vnet subnet create -g rg-net -n AzureBastionSubnet --vnet-name hub-vnet --address-prefixes 10.100.1.0/26. - Bastion Standard: Provisioned Bastion Standard:
az network bastion create -g rg-net -n bastion-prod --vnet-name hub-vnet --sku Standard --enable-tunneling true --enable-shareable-link true.
Configure Native SSH/RDP Tunneling via Azure CLI
Allow engineers to connect using their local terminal, SSH keys, and VS Code Remote SSH:
- CLI SSH Command: Engineers connect directly via
az network bastion ssh --name bastion-prod --resource-group rg-net --target-resource-id $VM_RESOURCE_ID --auth-type ssh-key --username adminuser --ssh-key ~/.ssh/id_rsa. - Generic TCP Tunneling: Tunneled internal private database ports to localhost:
az network bastion tunnel --name bastion-prod -g rg-net --target-resource-id $VM_RESOURCE_ID --resource-port 5432 --port 5432.
Generate Temporary Bastion Shareable Links for External Vendors
Provide zero-install browser access without requiring Azure subscription RBAC accounts:
- Create Shareable Link: Executed
az network bastion shareable-link create -g rg-net -n bastion-prod --vms $VM_RESOURCE_ID. - Vendor Access: Vendor opens the secure unique HTTPS URL directly in their web browser, logging into the target VM via HTML5 RDP/SSH with zero local client software required.
Lock Down Network Security Groups (NSGs) & Decommission Public VMs
Close all public inbound ports across all subnets in the virtual network:
- NSG Ingress Rule: Added NSG rule allowing inbound port 22/3389 strictly from the
AzureBastionSubnetCIDR block. - Decommission Legacy Jump Hosts: Safely wiped and terminated all public-facing bastion VMs, eliminating all public attack vectors.
- Deploy Azure Bastion Standard with tunneling and shareable links enabled.
- Enable developers to connect using native terminal SSH and VS Code via az network bastion ssh.
- Tunnel private database ports securely to localhost without VPNs.
- Decommission all public jump boxes and lock down NSGs to allow traffic only from AzureBastionSubnet.