This is an optional offering. Once deployed, users are responsible for its maintenance and updates. Feel free to ask for feedback in the #peer-support channel on EWC RocketChat.
The SSH proxy or SSH bastion is the barrier between your internal machines (without public or floating IPs) and the public internet. With the SSH proxy, you'll have an extra layer of security on top of your VMs. It's equipped with fail2ban, automatic security updates and more.
How to provision the SSH Bastion
If provisioning after October of 2025, we recommend deploying based on the community hub, to benefit form upcoming features or fixes.
Deployment based on the EWC Community Hub
Checkout the corresponding Community Hub Item.
Next steps
- How to connect to a VM hidden behind the SSH Bastion
- Troubleshooting - Remote host identification has changed