A jump host is not just another box in a diagram. It changes who authenticates where, which name is resolved, what must remain connected and who reviews the route.
Every line on the route map is paired with an owner and a verification point.
Route ledger
Segment
Record
Verify
Operator → gateway
Gateway name, SSH port, approved auth
Host identity and access policy
Gateway → target
Target name as gateway resolves it
Reachability and least privilege
Local listener
Bind address and local port
Exposure on the operator device
Service destination
Remote host and port
Application ownership
Design sequence
Start from a business destination, not a preferred tunneling feature.
Locate DNS, firewall, authentication and audit boundaries.
Select the simplest supported route that meets the boundary constraints.
Test from a non-privileged pilot account and record failure signals.