User Tools

Site Tools


services:rustdesk

# RustDesk Self-Hosted Relay Server

Self-hosted RustDesk relay server running on kabururd (Hetzner CX23, 46.224.187.74 — moved 2026-08-05 from kaburusvr for blast-radius isolation). Provides private relay infrastructure for remote desktop access across all managed clients, avoiding reliance on RustDesk public servers.

## What it does

RustDesk requires two server components:

- hbbs - ID/rendezvous server. Clients register here and discover each other. - hbbr - Relay server. Proxies traffic when direct peer-to-peer is not possible.

Both run as Docker containers on kaburusvr.uk using host networking.

## Location and files

Path Purpose
—————
/opt/rustdesk/ Project root
/opt/rustdesk/docker-compose.yml Compose definition
/opt/rustdesk/data/ Persistent data volume (mounted as /root in containers)
/opt/rustdesk/data/id_ed25519 Private key - keep safe, needed for client config
/opt/rustdesk/data/id_ed25519.pub Public key - distribute to clients
/opt/rustdesk/data/db_v2.sqlite3 Peer/registration database

## Docker setup

Image: rustdesk/rustdesk-server:latest (version 1.1.16 as of 2026-08-05) Network mode: host - containers share the server network stack directly. Restart policy: unless-stopped

The -r kaburu.cc argument on hbbs tells it which relay host to advertise to clients. Both containers share the same ./data volume.

## Ports used (host network)

Port Protocol Service Firewall (UFW)
—————-————————–
21115 TCP hbbs - NAT type test ALLOW Anywhere
21116 TCP hbbs - ID registration and heartbeat ALLOW Anywhere
21116 UDP hbbs - ID registration and heartbeat LIMIT (rate-limited 2026-08-05)
21117 TCP hbbr - relay traffic ALLOW Anywhere
21118 TCP hbbs - websocket (web client) BLOCKED since 2026-08-05
21119 TCP hbbr - websocket (web client) BLOCKED since 2026-08-05

21118/21119 are web-client only (browser-based access). Steve uses the desktop app, so they're closed at UFW to cut attack surface. Reopen with `ufw allow 21118/tcp && ufw allow 21119/tcp` if browser access is ever needed.

No fail2ban jail for hbbs/hbbr — their logs contain no failure signatures (all INFO: registration, relay pairing), so there's nothing to ban on. Rate-limited UDP 21116 instead.

## Client configuration

In the RustDesk client under Settings > Network > ID/Relay Server:

- ID Server: kaburu.cc - Relay Server: kaburu.cc - Key: contents of /opt/rustdesk/data/id_ed25519.pub

## History / move-back consideration (2026-08-05)

RustDesk originally lived on a DigitalOcean droplet (~$6/mo); moved to kaburusvr in May 2026 to save ~$5/mo. Moved back to a dedicated Hetzner CX23 (kabururd, 46.224.187.74, €5.49/mo + €0.50 IPv4) on 2026-08-05 — full blast-radius isolation from the production box (25 sites + mail + DNS). Same key, same hostname (kaburu.cc A record repointed), zero client reconfiguration. Old relay on kaburusvr kept running for 48h overlap, then decommissioned. See log 2026-08-05.

## kabururd (new home, since 2026-08-05)

- Hetzner CX23, Ubuntu 26.04 LTS, Nuremberg (same DC as kaburusvr) - Tailscale: 100.122.46.3, tag `server-hetzner` (matches kaburusvr ACL rules) - SSH: Tailscale-only (100.64.0.0/10) — same doctrine as kaburusvr - UFW: 21115/21116/21117 public, 21116/udp LIMIT, 21118/21119 blocked - Data at /opt/rustdesk/data (key + DB copied from kaburusvr — same id_ed25519) - ⚠️ Backup NOT yet wired to TrueNAS — next item

## Management commands

Check status:

cd /opt/rustdesk && docker compose ps

View logs:

docker logs rustdesk-hbbs --tail 50
docker logs rustdesk-hbbr --tail 50

Restart:

cd /opt/rustdesk && docker compose restart

Stop and start:

cd /opt/rustdesk && docker compose down
cd /opt/rustdesk && docker compose up -d

Update image:

cd /opt/rustdesk && docker compose pull && docker compose up -d

## Key backup

The id_ed25519 private key in /opt/rustdesk/data/ is critical. If lost, all clients need reconfiguring with a new key. Include this directory in server backups. Do not store the key value in this wiki - reference by path only.

## Notes

- Both containers use the same image; role is set by command (hbbs vs hbbr). - Host networking avoids Docker NAT issues with UDP on port 21116. - Set up 2026-05-05. Running stably as of 2026-05-12.

## Clients

### kaburu-a05m (DECOMMISSIONED 2026-07-04 — screen flicker hardware defect)

Replaced by: kaburu-laptop — Dell Precision 17“, Mint.

Field Value
——-——-
RustDesk ID `413560219` (historical)
Password `kaburu05m`
Relay `kaburu.cc` (self-hosted)
Install flatpak (user) — com.rustdesk.RustDesk 1.4.8
services/rustdesk.txt · Last modified: (external edit)

Donate Powered by PHP Valid HTML5 Valid CSS Driven by DokuWiki