Introduction to Boundary
Managing access to dynamic cloud infrastructure is hard. VPNs often expose the entire private network, SSH bastions require distributing and rotating credentials, and access policies can drift as resources change. HCP Boundary solves this by providing identity-based, just-in-time access to SSH, RDP, or TCP targets without distributing credentials or exposing the underlying network.
Boundary enables simple and secure access to dynamic infrastructure by providing:
Identity-based access controls: Streamline just-in-time access to privileged sessions (e.g. TCP, SSH, RDP) for users and applications. Tightly control access permissions with extensible role-based access controls.
Access Automation: Define your perimeter of resources, identities, and access controls as code through Boundary's fully-instrumented Terraform Provider, REST API, CLI, and SDK. Automate the discovery of new resources and enforcement of existing policies as resources are provisioned.
Session Visibility: Security administrators gain visibility into users accessing monitored targets. If necessary, the administrators can terminate the sessions from the Admin UI.

Traditional approaches like SSH bastion hosts or VPNs that require distributing and managing credentials, configure network controls like firewalls, and expose the private network. Boundary provides a secure way to access hosts and critical systems without having to manage credentials or expose your network.

Refer to the Boundary documentation page.
The Boundary getting started tutorials will walk you through your first Boundary project, highlighting major features of Boundary.
Knowledge checks
A quiz to test your knowledge.
What problem does HCP Boundary solve that traditional VPNs do not?
🔘 VPNs cannot encrypt traffic between clients and servers.
🔘 VPNs expose the entire private network and require distributing credentials.
🔘 VPNs do not support TCP or RDP protocols.
🔘 VPNs require a dedicated hardware appliance to operate.
❌ VPNs cannot encrypt traffic between clients and servers.
✅ VPNs expose the entire private network and require distributing credentials.
❌ VPNs do not support TCP or RDP protocols.
❌ VPNs require a dedicated hardware appliance to operate.
Why does HCP Boundary use identity-based access controls instead of network-based controls?
Identity-based access controls tie access permissions to verified user or application identities rather than network location, so only authorized principals can reach specific targets without exposing the broader private network or requiring distributed credentials.
What capability does HCP Boundary provide for security administrators to monitor active sessions?
🔘 Administrators can only review completed session logs after a session ends.
🔘 Administrators can view and terminate active sessions from the Admin UI.
🔘 Administrators must use a separate SIEM tool to monitor sessions.
🔘 Administrators can monitor sessions but cannot terminate them.
❌ Administrators can only review completed session logs after a session ends.
✅ Administrators can view and terminate active sessions from the Admin UI.
❌ Administrators must use a separate SIEM tool to monitor sessions.
❌ Administrators can monitor sessions but cannot terminate them.
Next steps
Getting Started tutorials will give you a quick tour of HCP Boundary. Follow the getting started tutorials in sequential order to complete them successfully.