Rust desk pro: self hosted, cross platform remote desktop solution

As commercial remote desktop solutions like TeamViewer and AnyDesk continue to raise prices, enforce strict connection limits, and bloat their software, IT teams are increasingly looking for alternatives. RustDesk has emerged as the definitive open-source answer.

While the free, open-source (OSS) version of RustDesk is fantastic for basic connectivity, RustDesk Server Pro introduces the enterprise features necessary for managing a fleet of devices: address books, granular user permissions, audit logs, Single Sign-On (OIDC/LDAP), and the ability to generate custom-branded clients with hardcoded security keys.

By self-hosting the Pro server on AWS, you gain complete data sovereignty, eliminate third-party relay bottlenecks, and bypass per-user subscription gouging. Here is how to architect and deploy it.

The Architecture: How RustDesk Connects

A self-hosted RustDesk deployment consists of two primary services, plus a web console for the Pro version:

  • hbbs (ID/Rendezvous Server): This acts as the central directory. When a RustDesk client boots up, it registers its ID and local IP with hbbs. When you try to connect to a remote machine, your client asks hbbs where to find it.
  • hbbr (Relay Server): RustDesk always attempts a direct Peer-to-Peer (P2P) connection first via TCP hole-punching. If strict carrier NATs or firewalls block the direct connection, traffic transparently falls back to hbbr, routing the encrypted video/control stream through your server.
  • API/Web Console (Pro Only): Runs alongside hbbs to provide the management GUI, handle database operations, and manage users and address books.

Prerequisites

To ensure a smooth, low-latency experience, you will need:

  • An AWS EC2 Instance: Use a t3.micro or t2.micro (Free Tier eligible) with Ubuntu 24.04 LTS.
  • A Public IP Address & Domain: A dedicated subdomain (e.g., remote.yourcompany.com) pointed to your EC2 instance’s Elastic IP.
  • Docker & Docker Compose: Installed and running on the host.

1. Configure AWS Security Groups

AWS uses “Security Groups” as a virtual firewall. You must open these ports in the AWS console under the Security tab of your EC2 instance. Without these, your server will be invisible to your clients.

ProtocolPortPurpose
TCP22SSH Access
TCP80, 443Web Console (HTTPS/Caddy)
TCP21115-21116hbbs
UDP21116hbbs (NAT hole-punching)
TCP21117hbbr
TCP21118-21119WebSocket signaling

Crucial: Ensure your “Inbound Rules” allow traffic to 443/tcp from the public internet, however the 21115-21119 port range should be restricted to a Prefix List in AWS. Read more about Prefix Lists in AWS here.

2. Deployment Walkthrough

Create the Directory Structure

Bash

sudo mkdir -p /opt/rustdesk-pro/data
cd /opt/rustdesk-pro

Create the Docker Compose File

Create docker-compose.yml. We use network_mode: host because port-mapping via Docker bridge networks can interfere with RustDesk’s NAT detection.

YAML

services:
hbbs:
container_name: hbbs
image: rustdesk/rustdesk-server-pro:latest
command: hbbs
network_mode: host
volumes:
- ./data:/root
restart: unless-stopped
hbbr:
container_name: hbbr
image: rustdesk/rustdesk-server-pro:latest
command: hbbr
network_mode: host
volumes:
- ./data:/root
restart: unless-stopped

Spin Up the Stack

Bash

sudo docker compose up -d

Retrieve your initial admin password from the logs:

Bash

sudo docker logs hbbs

3. Configure Let’s Encrypt with Caddy

Do not expose the raw Web Console (port 21114) to the internet. We will use Caddy, which automatically handles Let’s Encrypt SSL certificates.

  1. Install Caddy: Add Caddy to your docker-compose.yml or install it on the host system.
  2. Create a Caddyfile:Plaintextremote.yourcompany.com { reverse_proxy localhost:21114 }
  3. Run Caddy: If installed on the host, run caddy start. Caddy will automatically reach out to Let’s Encrypt, verify your domain (ensure your A-record points to the EC2 IP), and provision a valid SSL certificate.

Streamlining End-User Deployment

The biggest “Pro” advantage is the Custom Client Generator. From the web console (https://remote.yourcompany.com), you can build a .exe or .pkg file that has your server address and public key hardcoded. When your users install this version, they are automatically connected to your secure, private infrastructure without needing to touch a single configuration setting.