Mainframes remain the backbone of many of the world’s critical systems, processing millions of transactions per second while delivering near-continuous availability. From powering Wall Street transactions to travel bookings, mainframes are ubiquitous. Yet operator access to these platforms often still relies on traditional protocols such as HTTP(S), SSH, and Telnet, which can introduce security, governance, and audit challenges. For the mission-critical platforms that mainframes are, there should be a better default.
»Why traditional mainframe access needs to change
Mainframes provide incredible flexibility through logical partitions or LPARs, which let organizations divide a single physical system into multiple isolated environments for running many different operating systems, workloads, and applications. As shown below, mainframe administration typically involves two layers of management interfaces: the hardware management console (HMC) for provisioning and managing hardware resources, processor allocations, and LPAR configurations, and administrative consoles within each LPAR for managing the operating system, applications, and day-to-day operational tasks. Operators may use TN3270 or TN3270E for z/OS applications and consoles, SSH for z/OS UNIX System Services or Linux on IBM Z, and HTTPS for remote HMC access when enabled.

Overview of IBM Z architecture and access
These traditional access models often depend on static credentials, direct network connectivity, and fragmented audit trails, which can increase operational complexity and create opportunities for lateral movement through private mainframe networks. Teams commonly grant HMC dashboard access through long-lived usernames and passwords, often in browser sessions that lack centralized correlation with other access records. TN3270 connections often give operators standing privileges with broad access controls, while SSH access typically relies on long-lived SSH keys that are shared across teams and rarely rotated. These are deployment issues, not inherent properties of HTTPS, TN3270, or SSH protocols.
Shared credentials limit identity context and make it difficult to map actions to specific individuals. VPNs, jump hosts, external port openings, and other network access requirements add operational burden and expand the attack surface. Limited centralized visibility into access details and logs makes it harder to enforce zero trust principles, provide comprehensive session visibility, and satisfy compliance requirements. HashiCorp Boundary addresses these challenges by brokering access through trusted identities and policies, centralizing session metadata, and enabling session monitoring without exposing long-lived credentials to operators.
»How Boundary modernizes and secures mainframe access
Boundary is an identity-based privileged access management platform that can provide secure, policy-controlled access to dynamic hosts and services. Boundary grants access based on identity, with support for identity providers such as Okta, Ping Identity, and other OIDC-compliant providers, and on policy, with predefined roles that determine which systems an operator can access. It can broker policy-authorized connections across the three access paths to mainframes discussed above – HTTPS for HMC access, and SSH/TN3270 for LPAR access. For HMC access, Boundary can authorize and proxy the network connection to the web dashboard as a generic TCP target, but credential injection is currently not supported. For LPAR access, Boundary can minimize operator reliance on static credentials. Boundary improves security and operator experience by handling the credentials needed for these connections: It injects credentials for transparent SSH sessions and brokers credentials for TN3270 sessions. Additionally, when integrated with HashiCorp Vault Enterprise, HCP Vault Dedicated, or IBM Vault Self-Managed for Z and LinuxOne, Boundary can provide the just-in-time credentials required for these connections. Boundary also offers teams a consistent, centralized management plane for audit records, including session recordings for SSH connections.
Demo of secure, transparent mainframe SSH and TN3270 sessions with Boundary
»Reference architecture for Boundary-secured mainframe access
To secure operator access to mainframes, teams can use HCP Boundary as a HashiCorp-managed control plane or deploy Boundary Enterprise as a self-managed control plane. In either model, a mainframe-adjacent Boundary worker runs the Boundary service on a standard Linux VM or server in the same network as the mainframe, establishes an encrypted outbound connection to the Boundary control plane, and proxies authorized sessions to the mainframe targets.

Reference Boundary architecture for secure mainframe access
The schematic above shows a basic setup. Plan for outbound/egress connectivity from the worker to the Boundary control plane and outbound connectivity from the worker to the target. Teams can also implement multi-hop architectures with Boundary when their network topology requires it; Boundary still abstracts that complexity from the end user or operator and selects the best path for connecting the client to the target. Vault integration enables just-in-time credential injection for SSH connections and credential brokering for TN3270 connections. As summarized below, teams can use several Vault deployment patterns with Boundary to secure mainframe access:
Vault deployment | Dynamic SSH certificate | Dynamic RACF passphrase |
HCP Vault Dedicated or Vault Enterprise | ✓ | ✓ |
IBM Vault Self-Managed for Z and LinuxOne | ✓ | ✓ |
»Where this fits your environment
This approach is most valuable for teams that need to reduce standing access, centralize authorization decisions, and improve audit visibility across both modern and traditional mainframe administration paths. Rather than replacing established HMC, SSH, or TN3270 workflows, Boundary can sit in front of them as a controlled access layer that adds identity-based authorization, short-lived credentials where supported, and centralized session context.
Boundary is a strong fit for organizations that want to modernize mainframe access without broadly exposing target networks or disrupting established operational practices. By placing a mainframe-adjacent worker near HMC and LPAR targets, teams can broker authorized access through a consistent identity and policy layer while preserving network isolation from direct user access.
To explore how Boundary can support your mainframe access modernization journey, review the resources below or contact your HashiCorp account team.









