Scaffold the CDK stack for a self-hosted RustDesk Server Pro relay so remote support no longer depends on the public RustDesk rendezvous/relay infrastructure. Single ARM64 EC2 (SSM-managed, no SSH) runs hbbs+hbbr in Docker. The server key pair and DB live on a standalone RETAINed EBS volume so they survive instance replacement (clients keep trusting the same key). Relay ports are public; the Pro admin console (21114) is restricted to the office VPN + VPC. IMDSv2 is enforced and the data dir is locked to root. EIP + rustdesk.seahaven.com give clients a stable address.
20 lines
350 B
YAML
20 lines
350 B
YAML
name: Deploy
|
|
on:
|
|
push:
|
|
branches: [main]
|
|
|
|
permissions:
|
|
id-token: write
|
|
contents: read
|
|
|
|
concurrency:
|
|
group: deploy
|
|
cancel-in-progress: false
|
|
|
|
jobs:
|
|
deploy:
|
|
uses: Sea-Haven-Industries/.github/.github/workflows/cd-cdk.yaml@main
|
|
with:
|
|
node-version: "24"
|
|
secrets:
|
|
deploy-role-arn: ${{ secrets.AWS_DEPLOY_ROLE_ARN }}
|