Bastion hosts are shared. VPN access is all-or-nothing. SSH keys are hard to rotate. Boundary gives each user identity-based, just-in-time access to specific targets — with full session recording.
How Boundary Works
User → Authenticate (OIDC/LDAP) → Request Access → Boundary Proxy → Target
↓
Session RecordedNo VPN. No bastion. No SSH keys distributed to users. Boundary creates a temporary, authenticated tunnel to the target.
Installation
# Install Boundary
brew install hashicorp/tap/boundary
# Start dev server
boundary dev
# Or production on Kubernetes
helm install boundary hashicorp/boundary \
--namespace boundary --create-namespaceCore Concepts
Organization → Project → Host Catalog → Host Set → Target
↓
Credential Store → Credential Library- Organization: Top-level tenant
- Project: Group of related resources
- Host Catalog: Where targets live (static IPs, AWS, Azure)
- Target: A specific resource (database, server, K8s cluster)
- Credential Store: Where credentials come from (Vault)
Master this topic with hands-on labs
Go beyond reading — build real projects in sandboxed environments with expert video guidance.
Browse Courses →Connect to a Database
Define the Target
# Create a target for the production database
boundary targets create tcp \
-name "prod-postgres" \
-scope-id p_project123 \
-default-port 5432 \
-session-max-seconds 3600
# Add the host
boundary hosts create static \
-name "prod-db" \
-address "10.0.1.50" \
-host-catalog-id hcst_catalog123
boundary host-sets add-hosts \
-id hsst_hostset123 \
-host hst_host123Connect
# User authenticates and connects
boundary connect postgres \
-target-id ttcp_target123 \
-dbname orders
# Boundary creates a local proxy
# psql connects through it
# Session is recorded and auditableThe user never sees the database IP, credentials, or network path.
Dynamic Credentials with Vault
# Link Boundary to Vault
boundary credential-stores create vault \
-scope-id p_project123 \
-vault-address https://vault.myorg.com \
-vault-token <token>
# Create credential library
boundary credential-libraries create vault-generic \
-credential-store-id csvlt_store123 \
-vault-path "database/creds/readonly" \
-credential-type username_passwordWhen a user connects: 1. Boundary requests temporary credentials from Vault 2. Vault generates a short-lived database user 3. User connects with temporary credentials 4. Credentials expire after the session
No standing credentials. No shared passwords.
SSH Access
# Connect to a server via SSH
boundary connect ssh \
-target-id ttcp_ssh_target \
-username ubuntu
# Or with injected credentials (from Vault)
boundary connect ssh \
-target-id ttcp_ssh_target
# Boundary injects SSH key automaticallyNo SSH keys on the user's laptop. No authorized_keys to manage. Boundary handles it.
Get weekly IT automation tips
Docker, Ansible, Terraform, MLOps — curated insights delivered to your inbox. No spam.
Subscribe Free →Session Recording
# List recorded sessions
boundary sessions list -scope-id p_project123
# Session details
boundary sessions read -id s_session123
# User: alice@myorg.com
# Target: prod-postgres
# Duration: 23 minutes
# Bytes transferred: 1.2 MB
# Connection time: 2026-02-01T14:30:00ZEvery connection is logged: who, what, when, how long. Compliance teams can audit access without reviewing firewall logs.
Dynamic Host Catalogs
Auto-discover targets from cloud providers:
# AWS EC2 discovery
boundary host-catalogs create plugin \
-scope-id p_project123 \
-plugin-name aws \
-attr region=eu-west-1 \
-secret access_key_id=$AWS_ACCESS_KEY \
-secret secret_access_key=$AWS_SECRET_KEY
# Filter to specific instances
boundary host-sets create plugin \
-host-catalog-id hcplg_catalog123 \
-attr "filters=tag:Environment=production"New EC2 instances with the production tag are automatically available as Boundary targets.
Boundary vs Alternatives
| Feature | Boundary | Teleport | Bastion Host | VPN |
|---|---|---|---|---|
| Identity-based | Yes | Yes | No | No |
| Session recording | Yes | Yes | Manual | No |
| Dynamic credentials | Yes (Vault) | Limited | No | No |
| No VPN needed | Yes | Yes | No | N/A |
| Cloud discovery | Yes | Yes | No | No |
| Credential injection | Yes | SSH certs | SSH keys | N/A |
| Audit trail | Built-in | Built-in | Logs | Logs |
Use Boundary when you need Vault integration and dynamic credentials. Use Teleport for simpler setups with built-in certificate authority. Both are better than bastion hosts and VPNs.
---
Ready to go deeper? Master infrastructure security with hands-on courses at CopyPasteLearn.
Ready to learn by doing?
Stop reading tutorials — start building. Expert video courses with hands-on labs in real sandboxed environments.
Related Articles
SSH Key Setup and Hardening Guide
Set up SSH keys and harden your server. Key generation, agent forwarding, config file management, and security tips for remote access.
Tailscale Zero Trust Networking
Tailscale creates a WireGuard mesh network for zero trust access to servers, Kubernetes clusters, and databases. Learn how Tailscale replaces VPNs.
Vault Secrets Management Guide
Manage secrets with HashiCorp Vault. KV engine, dynamic credentials, auth methods, policies, and Kubernetes integration patterns.
Building Custom OpenClaw Skills
Learn how to create, package, and share custom skills for OpenClaw agents. From simple automations to complex integrations.
Building REST APIs with Node.js
Learn how to build production-ready REST APIs with Node.js and Express — routing, middleware, error handling, and best practices.
Buildpacks vs Dockerfiles Comparison
Cloud Native Buildpacks automatically detect and build your app without a Dockerfile. Compare Buildpacks and Dockerfiles for build speed, security.
Explore topics
Browse more articles on the topics covered here.