The requireImdsv2 aspect names its launch template "<id>LaunchTemplate" by default, which collided with an existing account-global InstanceLaunchTemplate and failed the first deploy. Enabling @aws-cdk/aws-ec2:uniqueImdsv2TemplateName makes the name hash-unique. |
||
|---|---|---|
| .github | ||
| bin | ||
| docker | ||
| lib | ||
| userdata | ||
| .gitignore | ||
| cdk.context.json | ||
| cdk.json | ||
| package-lock.json | ||
| package.json | ||
| README.md | ||
| RUNBOOK.md | ||
| tsconfig.json | ||
rustdesk-server
Self-hosted RustDesk Server Pro (remote-desktop relay + rendezvous) for Sea Haven Industries, deployed to AWS via CDK.
Status: scaffold — not yet deployed. See First deploy.
Architecture
A single ARM64 EC2 instance runs RustDesk Server Pro (hbbs rendezvous/ID + hbbr relay) in Docker. Clients connect from anywhere over the public internet to a stable Elastic IP fronted by rustdesk.seahaven.com.
RustDesk clients (anywhere)
│ TCP 21114-21119 / UDP 21116
▼
Elastic IP ──► EC2 t4g.small (AL2023 arm64, SSM-managed)
│ Docker: hbbs + hbbr (network_mode: host)
├─ /dev/xvda 20 GiB root (OS only, ephemeral)
└─ /var/lib/rustdesk ◄── standalone EBS 20 GiB (RETAIN)
key pair + sled DB
Nightly DLM snapshots (retain 30, tag rustdesk-backup=true)
All durable state (the id_ed25519 server key pair and the sled database) lives on a standalone, RETAINed EBS data volume, never an inline block device, so it survives instance replacement and stack deletion. See RUNBOOK.md.
Ports
| Port | Proto | Purpose | Exposure |
|---|---|---|---|
| 21114 | TCP | Pro web console / API | VPN/VPC only (10.10.0.0/16, 10.20.0.0/16) |
| 21115 | TCP | hbbs NAT type test | public |
| 21116 | TCP + UDP | hbbs registration / hole punch / heartbeat | public |
| 21117 | TCP | hbbr relay | public |
| 21118 | TCP | hbbs web client (websocket) | public |
| 21119 | TCP | hbbr web client (websocket) | public |
Relay/rendezvous ports are public so clients connect from anywhere. The Pro admin console (21114) is restricted to the office VPN + VPC, so you administer the server and activate the Pro license over VPN. To take the relay VPN-only later, flip the public flags in RUSTDESK_PORTS in the stack.
Resources
- EC2
rustdesk-server— AL2023 arm64,t4g.small, SSM-managed (no inbound SSH) - EBS data volume
rustdesk-data— 20 GiB GP3, encrypted,RemovalPolicy.RETAIN, attached at/dev/xvdf - Elastic IP — stable public address, associated to the instance
- Security group
rustdesk-server— RustDesk ports above - IAM role
rustdesk-server-instance—AmazonSSMManagedInstanceCore+secretsmanager:GetSecretValueonrustdesk/* - DLM
rustdesk-server-dlm— nightly instance snapshots, retain 30 - Route 53 A record
rustdesk.seahaven.com→ EIP
Configuration
Secrets (Secrets Manager) — created out of band
| Secret | Contents |
|---|---|
rustdesk/server-key-pair |
id_ed25519 private + .pub public key generated by hbbs on first boot (mirror up post-deploy so a replacement host keeps the same key) |
rustdesk/pro-license |
RustDesk Server Pro license key |
SSM parameters (non-secret)
| Parameter | Purpose |
|---|---|
/rustdesk-server/relay-host |
Public hostname clients use (rustdesk.seahaven.com) |
The pinned Docker image tag lives in lib/rustdesk-server-stack.ts (RUSTDESK_IMAGE_TAG).
Deployment
CI/CD runs through the reusable org workflows (ci-typescript-cdk.yaml, cd-cdk.yaml). Pushes to main deploy automatically.
npm ci
npx cdk diff
npx cdk deploy
First deploy
- Confirm a public subnet ID in
us-east-1aand setPUBLIC_SUBNET_IDinlib/rustdesk-server-stack.ts(replacesubnet-REPLACE_ME). - Verify/pin
RUSTDESK_IMAGE_TAG. - Create the OIDC deploy role
githubdeploy-rustdesk-serverand the repo secretAWS_DEPLOY_ROLE_ARN. cdk deploy(or push tomain). The instance boots, pulls the images, andhbbsgenerates the key pair on the empty data volume.- SSM in, read
/var/lib/rustdesk/id_ed25519{,.pub}, store intorustdesk/server-key-pair. - Over the office VPN, open
http://rustdesk.seahaven.com:21114, activate the Pro license, create users (the console is not reachable off-VPN). - Point a test client at
rustdesk.seahaven.com+ the public key; confirm a session relays.
Operations
See RUNBOOK.md for key rotation, restore-from-snapshot, and instance replacement.