A secure computer that acts as a gateway for accessing private servers that aren't exposed to the internet. Like a security checkpoint at a building entrance - you must go through it to reach the protected areas inside.
Instead of giving your database server a public IP address, you connect to a Bastion Host first, then securely access the database from there. Azure Bastion, AWS Session Manager, and GCP IAP all provide this service.