The README described the deployed architecture and resources but never
documented that the repo itself is a CDK v2 app, leaving cdk.json and
the bin/lib layout unexplained for anyone opening the codebase.
Add a "CDK app" section mapping cdk.json, bin/app.ts, the stack file,
cdk.context.json, and the TypeScript config to their roles, so the
infrastructure-as-code component is discoverable from the README.
Scaffold the CDK stack for a self-hosted RustDesk Server Pro relay so
remote support no longer depends on the public RustDesk rendezvous/relay
infrastructure.
Single ARM64 EC2 (SSM-managed, no SSH) runs hbbs+hbbr in Docker. The
server key pair and DB live on a standalone RETAINed EBS volume so they
survive instance replacement (clients keep trusting the same key). Relay
ports are public; the Pro admin console (21114) is restricted to the
office VPN + VPC. IMDSv2 is enforced and the data dir is locked to root.
EIP + rustdesk.seahaven.com give clients a stable address.