5 KiB
rustdesk-server
Self-hosted RustDesk Server Pro (remote-desktop relay + rendezvous) for Sea Haven Industries, deployed to AWS via CDK.
Status: scaffold — not yet deployed. See First deploy.
Architecture
A single ARM64 EC2 instance runs RustDesk Server Pro (hbbs rendezvous/ID + hbbr relay) in Docker. Clients connect from anywhere over the public internet to a stable Elastic IP fronted by rustdesk.seahaven.com.
RustDesk clients (anywhere)
│ TCP 21114-21119 / UDP 21116
▼
Elastic IP ──► EC2 t4g.small (AL2023 arm64, SSM-managed)
│ Docker: hbbs + hbbr (network_mode: host)
├─ /dev/xvda 20 GiB root (OS only, ephemeral)
└─ /var/lib/rustdesk ◄── standalone EBS 20 GiB (RETAIN)
key pair + sled DB
Nightly DLM snapshots (retain 30, tag rustdesk-backup=true)
All durable state (the id_ed25519 server key pair and the sled database) lives on a standalone, RETAINed EBS data volume, never an inline block device, so it survives instance replacement and stack deletion. See RUNBOOK.md.
Documentation
The canonical map of Sea Haven's AWS infrastructure lives in Confluence. This project's rustdesk-server stack is represented there as a Mermaid subgraph.
- AWS Architecture Map (Confluence, IT space, page 1540098)
Ports
| Port | Proto | Purpose | Exposure |
|---|---|---|---|
| 21114 | TCP | Pro web console / API | VPN/VPC only (10.10.0.0/16, 10.20.0.0/16) |
| 21115 | TCP | hbbs NAT type test | public |
| 21116 | TCP + UDP | hbbs registration / hole punch / heartbeat | public |
| 21117 | TCP | hbbr relay | public |
| 21118 | TCP | hbbs web client (websocket) | public |
| 21119 | TCP | hbbr web client (websocket) | public |
Relay/rendezvous ports are public so clients connect from anywhere. The Pro admin console (21114) is restricted to the office VPN + VPC, so you administer the server and activate the Pro license over VPN. To take the relay VPN-only later, flip the public flags in RUSTDESK_PORTS in the stack.
Resources
- EC2
rustdesk-server— AL2023 arm64,t4g.small, SSM-managed (no inbound SSH) - EBS data volume
rustdesk-data— 20 GiB GP3, encrypted,RemovalPolicy.RETAIN, attached at/dev/xvdf - Elastic IP — stable public address, associated to the instance
- Security group
rustdesk-server— RustDesk ports above - IAM role
rustdesk-server-instance—AmazonSSMManagedInstanceCore+secretsmanager:GetSecretValueonrustdesk/* - DLM
rustdesk-server-dlm— nightly instance snapshots, retain 30 - Route 53 A record
rustdesk.seahaven.com→ EIP
Configuration
Secrets (Secrets Manager) — created out of band
| Secret | Contents |
|---|---|
rustdesk/server-key-pair |
id_ed25519 private + .pub public key generated by hbbs on first boot (mirror up post-deploy so a replacement host keeps the same key) |
rustdesk/pro-license |
RustDesk Server Pro license key |
SSM parameters (non-secret)
| Parameter | Purpose |
|---|---|
/rustdesk-server/relay-host |
Public hostname clients use (rustdesk.seahaven.com) |
The pinned Docker image tag lives in lib/rustdesk-server-stack.ts (RUSTDESK_IMAGE_TAG).
Deployment
CI/CD runs through the reusable org workflows (ci-typescript-cdk.yaml, cd-cdk.yaml). Pushes to main deploy automatically.
npm ci
npx cdk diff
npx cdk deploy
First deploy
- Confirm a public subnet ID in
us-east-1aand setPUBLIC_SUBNET_IDinlib/rustdesk-server-stack.ts(replacesubnet-REPLACE_ME). - Verify/pin
RUSTDESK_IMAGE_TAG. - Create the OIDC deploy role
githubdeploy-rustdesk-serverand the repo secretAWS_DEPLOY_ROLE_ARN. cdk deploy(or push tomain). The instance boots, pulls the images, andhbbsgenerates the key pair on the empty data volume.- SSM in, read
/var/lib/rustdesk/id_ed25519{,.pub}, store intorustdesk/server-key-pair. - Over the office VPN, open
http://rustdesk.seahaven.com:21114, activate the Pro license, create users (the console is not reachable off-VPN). - Point a test client at
rustdesk.seahaven.com+ the public key; confirm a session relays.
Operations
See RUNBOOK.md for key rotation, restore-from-snapshot, and instance replacement.