3 ms·
You probably already have CI/CD so a scheduled action on something like running Terraform would notice that your VM OS image version just got updated and automa
by no_circuit 4y ago
You probably already have CI/CD so a scheduled action on something like running Terraform would notice that your VM OS image version just got updated and automatically replace your bastion. That image seems to update every few days. You don't lose any data since persistent disk(s) are attached. I'd be surprised if anyone with automation still manually logs into machines to run apt-get update and upgrade -- cloud-init and/or crontab should do that for you.
If there aren't any DNS entries pointing to my bastion host(s), then I'd find it unlikely that a DDoS would ever specifically be directed to them. Pretty easy to recreate them in another region, and/or put them behind something like Cloudflare.