For folks on AWS I highly recommend investing in SSH over SSM in combination with EC2 Instance Connect. You can generate temporary ssh keys, send it to EC2 Instance Connect, it'll be on the server for 60 seconds. Then you can use ssm start-session to connect to the server over SSM. This also allows you to disable SSH ingress, and doesn't need a bastion or VPN.