The author seems to have a solution to sell so that puts me on alert, but this is the only post I could find suggesting bastion hosts are not a good idea.
I think jump servers are like app pools in IIS - they're not necessarily a good idea anymore, and can introduce problems, but they're not "considered harmful" yet.
This HN thread has a lot of back and forth on bastions vs VPNs: https://news.ycombinator.com/item?id=8637154
Basically, I'm trying to migrate our bare metal servers into an AWS and am looking for best practices. I've more or less followed this guide so far: http://blog.bwhaley.com/reference-vpc-architecture