As commercial remote desktop solutions like TeamViewer and AnyDesk continue to raise prices, enforce strict connection limits, and bloat their software, IT teams are increasingly looking for alternatives. RustDesk has emerged as the definitive open-source answer.
While the free, open-source (OSS) version of RustDesk is fantastic for basic connectivity, RustDesk Server Pro introduces the enterprise features necessary for managing a fleet of devices: address books, granular user permissions, audit logs, Single Sign-On (OIDC/LDAP), and the ability to generate custom-branded clients with hardcoded security keys.
By self-hosting the Pro server on AWS, you gain complete data sovereignty, eliminate third-party relay bottlenecks, and bypass per-user subscription gouging. Here is how to architect and deploy it.
The Architecture: How RustDesk Connects
A self-hosted RustDesk deployment consists of two primary services, plus a web console for the Pro version:
- hbbs (ID/Rendezvous Server): This acts as the central directory. When a RustDesk client boots up, it registers its ID and local IP with
hbbs. When you try to connect to a remote machine, your client askshbbswhere to find it. - hbbr (Relay Server): RustDesk always attempts a direct Peer-to-Peer (P2P) connection first via TCP hole-punching. If strict carrier NATs or firewalls block the direct connection, traffic transparently falls back to
hbbr, routing the encrypted video/control stream through your server. - API/Web Console (Pro Only): Runs alongside
hbbsto provide the management GUI, handle database operations, and manage users and address books.
Prerequisites
To ensure a smooth, low-latency experience, you will need:
- An AWS EC2 Instance: Use a
t3.microort2.micro(Free Tier eligible) with Ubuntu 24.04 LTS. - A Public IP Address & Domain: A dedicated subdomain (e.g.,
remote.yourcompany.com) pointed to your EC2 instance’s Elastic IP. - Docker & Docker Compose: Installed and running on the host.
1. Configure AWS Security Groups
AWS uses “Security Groups” as a virtual firewall. You must open these ports in the AWS console under the Security tab of your EC2 instance. Without these, your server will be invisible to your clients.
| Protocol | Port | Purpose |
| TCP | 22 | SSH Access |
| TCP | 80, 443 | Web Console (HTTPS/Caddy) |
| TCP | 21115-21116 | hbbs |
| UDP | 21116 | hbbs (NAT hole-punching) |
| TCP | 21117 | hbbr |
| TCP | 21118-21119 | WebSocket signaling |
Crucial: Ensure your “Inbound Rules” allow traffic to 443/tcp from the public internet, however the 21115-21119 port range should be restricted to a Prefix List in AWS. Read more about Prefix Lists in AWS here.
2. Deployment Walkthrough
Create the Directory Structure
Bash
sudo mkdir -p /opt/rustdesk-pro/datacd /opt/rustdesk-pro
Create the Docker Compose File
Create docker-compose.yml. We use network_mode: host because port-mapping via Docker bridge networks can interfere with RustDesk’s NAT detection.
YAML
services: hbbs: container_name: hbbs image: rustdesk/rustdesk-server-pro:latest command: hbbs network_mode: host volumes: - ./data:/root restart: unless-stopped hbbr: container_name: hbbr image: rustdesk/rustdesk-server-pro:latest command: hbbr network_mode: host volumes: - ./data:/root restart: unless-stopped
Spin Up the Stack
Bash
sudo docker compose up -d
Retrieve your initial admin password from the logs:
Bash
sudo docker logs hbbs
3. Configure Let’s Encrypt with Caddy
Do not expose the raw Web Console (port 21114) to the internet. We will use Caddy, which automatically handles Let’s Encrypt SSL certificates.
- Install Caddy: Add Caddy to your
docker-compose.ymlor install it on the host system. - Create a
Caddyfile:Plaintextremote.yourcompany.com { reverse_proxy localhost:21114 } - Run Caddy: If installed on the host, run
caddy start. Caddy will automatically reach out to Let’s Encrypt, verify your domain (ensure your A-record points to the EC2 IP), and provision a valid SSL certificate.
Streamlining End-User Deployment
The biggest “Pro” advantage is the Custom Client Generator. From the web console (https://remote.yourcompany.com), you can build a .exe or .pkg file that has your server address and public key hardcoded. When your users install this version, they are automatically connected to your secure, private infrastructure without needing to touch a single configuration setting.