Tailscale
The first boundary is the network itself. We use Tailscale to create a private, encrypted mesh network between authorized devices and internal resources. Our internal management tools are not sitting on the public internet waiting for someone to find a login page. A device must first be authorized to participate in our Tailscale network before it can even attempt to reach those services. An unauthorized party would first have to somehow gain access to an authorized device or otherwise satisfy the controls governing our private network — otherwise, the internal application simply isn't reachable.