Scaffold the CDK stack for a self-hosted RustDesk Server Pro relay so remote support no longer depends on the public RustDesk rendezvous/relay infrastructure. Single ARM64 EC2 (SSM-managed, no SSH) runs hbbs+hbbr in Docker. The server key pair and DB live on a standalone RETAINed EBS volume so they survive instance replacement (clients keep trusting the same key). Relay ports are public; the Pro admin console (21114) is restricted to the office VPN + VPC. IMDSv2 is enforced and the data dir is locked to root. EIP + rustdesk.seahaven.com give clients a stable address.
23 lines
736 B
YAML
23 lines
736 B
YAML
# Reference copy only. The authoritative compose file is rendered onto the
|
|
# instance by userdata/bootstrap.sh (with the pinned image tag injected from
|
|
# lib/rustdesk-server-stack.ts). Keep this in sync for documentation purposes.
|
|
# RustDesk Server Pro persists its key pair + DB to /root inside the container.
|
|
services:
|
|
hbbs:
|
|
container_name: hbbs
|
|
image: rustdesk/rustdesk-server-pro:1.8.4
|
|
command: hbbs
|
|
network_mode: host
|
|
volumes:
|
|
- /var/lib/rustdesk:/root
|
|
depends_on:
|
|
- hbbr
|
|
restart: unless-stopped
|
|
hbbr:
|
|
container_name: hbbr
|
|
image: rustdesk/rustdesk-server-pro:1.8.4
|
|
command: hbbr
|
|
network_mode: host
|
|
volumes:
|
|
- /var/lib/rustdesk:/root
|
|
restart: unless-stopped
|