Bastion in Oracle Cloud Infrastructure Bastion provides restricted and time-limited access to target resources that don't have public endpoints.
OCI Bastion is a public-facing service.
OCI Bastion does not require a public subnet on your end.
You don't need a public ip for this.
You connect to the public endpoint of OCI Bastion from the internet.
OCI Bastion then authenticates you and establishes a secure, encrypted connection to your private virtual network (VCN).
Once authenticated, you can access resources within your VCN through OCI Bastion.
See OCI Bastion Overview ->
https://docs.oracle.com/en-us/iaas/Content/Bastion/Concepts/bastionoverview.htm