#!/bin/bash # RustDesk Server Pro bootstrap (Amazon Linux 2023, ARM64). # Rendered by lib/rustdesk-server-stack.ts; __RUSTDESK_IMAGE_TAG__ is replaced # at synth time. Idempotent: safe to re-run on instance replacement. set -euxo pipefail RUSTDESK_DATA=/var/lib/rustdesk RUSTDESK_IMAGE="rustdesk/rustdesk-server-pro:__RUSTDESK_IMAGE_TAG__" # ── Persistent data volume (attached at /dev/xvdf via CfnVolumeAttachment; # surfaces as an nvme device on Nitro). Wait for it, then mount WITHOUT # reformatting if it already holds a filesystem (preserves the server key). ── until lsblk -dno NAME | grep -v "$(lsblk -no PKNAME "$(findmnt -n -o SOURCE /)" 2>/dev/null || echo xvda)" | grep -q .; do echo 'Waiting for data volume...' sleep 5 done DATA_DEVICE=/dev/$(lsblk -dno NAME | grep -v "$(lsblk -no PKNAME "$(findmnt -n -o SOURCE /)" 2>/dev/null || echo xvda)" | head -1) if ! blkid "$DATA_DEVICE"; then mkfs.ext4 -L rustdesk-data "$DATA_DEVICE" fi mkdir -p "$RUSTDESK_DATA" grep -q 'LABEL=rustdesk-data' /etc/fstab || \ echo "LABEL=rustdesk-data $RUSTDESK_DATA ext4 defaults,nofail 0 2" >> /etc/fstab mount -a # Restrict the data dir so the server private key (id_ed25519, created inside the # container at /root) is not readable by any non-root host user even if the # container writes it world-readable. chmod 700 "$RUSTDESK_DATA" # ── Docker + compose plugin ────────────────────────────────────────── dnf install -y docker systemctl enable --now docker DOCKER_CLI_PLUGINS=/usr/local/lib/docker/cli-plugins mkdir -p "$DOCKER_CLI_PLUGINS" curl -fsSL "https://github.com/docker/compose/releases/download/v2.29.7/docker-compose-linux-aarch64" \ -o "$DOCKER_CLI_PLUGINS/docker-compose" chmod +x "$DOCKER_CLI_PLUGINS/docker-compose" # ── Compose definition (host networking; SG is the access control) ─── mkdir -p /opt/rustdesk cat > /opt/rustdesk/docker-compose.yml << COMPOSE services: hbbs: container_name: hbbs image: ${RUSTDESK_IMAGE} command: hbbs network_mode: host volumes: - ${RUSTDESK_DATA}:/root depends_on: - hbbr restart: unless-stopped hbbr: container_name: hbbr image: ${RUSTDESK_IMAGE} command: hbbr network_mode: host volumes: - ${RUSTDESK_DATA}:/root restart: unless-stopped COMPOSE cd /opt/rustdesk docker compose pull docker compose up -d # Activate the Pro license and configure users in the web console at # http://rustdesk.seahaven.com:21114 after first boot. The generated key pair # lives at $RUSTDESK_DATA/id_ed25519{,.pub} -- mirror it into the # rustdesk/server-key-pair secret (see RUNBOOK).