Multiple factors:
1FA: Password(1F) OR private key (password blank)(1F)
2FA: Private key(1F) with password(2F)
MFA: Private key(1F), w/ password(2F) AND OTP(3F)
Ssh has 2fa options if that's the real reason.
Fwiw, this guide also suggests setting up a wg connection which is no better than ssh, and probably worse in some ways.
https://docs.aws.amazon.com/systems-manager/latest/userguide...
Google Cloud has a similar gcloud compute ssh instance-name command, and I imagine there's a similar one on azure.
One could have a box with no public IP and no open ports and still use this to connect.
Via ssh? With an SSH key? Over port 22?
No, through their in-house proxy tools such as Session Manager or Identity Aware Proxy or whatever Azure has.
> With an SSH key?
Not at the edge, and not an SSH key you manage. A dynamically generated one managed by the cloud provider which exists just for that session. So, not really, not like you're thinking.
> Over port 22?
For the tunnel? No.