Commercial remote desktop tools like TeamViewer and AnyDesk have become increasingly burdensome for businesses. Sudden connection timeouts, false commercial-use flags, and escalating annual licensing fees make third-party cloud relays an ongoing headache.
RustDesk is an open-source, full-featured remote desktop alternative that lets you host your own rendezvous signaling (hbbs) and relay (hbbr) servers. When you run your own RustDesk infrastructure, your screen data stays encrypted within your own network boundary, connections establish with near-zero latency, and you pay zero per-seat subscription fees.
Prerequisites
- A Linux server (Debian, Ubuntu, or Rocky Linux) or local homelab/on-premises box.
- Docker and Docker Compose installed.
- A static IP or public DNS domain (e.g.
remote.yourdomain.com) pointed to your host.
Step 1: Create the Project Directory
Create a dedicated directory to store your RustDesk compose file and data keys:
mkdir -p /opt/rustdesk-server && cd /opt/rustdesk-server
Step 2: Create the Docker Compose File
Save the following configuration as docker-compose.yml. Replace remote.yourdomain.com with your server's domain or public IP:
services:
hbbs:
container_name: rustdesk-hbbs
image: rustdesk/rustdesk-server:latest
command: hbbs -r remote.yourdomain.com:21117 -k _
volumes:
- ./data:/root
network_mode: host
restart: unless-stopped
hbbr:
container_name: rustdesk-hbbr
image: rustdesk/rustdesk-server:latest
command: hbbr -k _
volumes:
- ./data:/root
network_mode: host
restart: unless-stopped
-k _ flag: This forces clients to authenticate using your server's unique public encryption key. This prevents unauthorized third parties from using your relay server as an open proxy.
Step 3: Required Firewall Ports
Ensure the following ports are open on your server firewall or router NAT port-forwarding:
- 21115 (TCP): NAT type test
- 21116 (TCP/UDP): ID registration and heartbeat server
- 21117 (TCP): Relay service
- 21118 / 21119 (TCP): Web client support (optional)
# UFW Example
sudo ufw allow 21115:21119/tcp
sudo ufw allow 21116/udp
sudo ufw reload
Step 4: Launch the Server and Retrieve Your Public Key
Start the RustDesk server stack in the background:
docker compose up -d
Retrieve the automatically generated public key from the data directory:
cat ./data/id_ed25519.pub
Copy this key string. You will need it to configure your RustDesk desktop and mobile client apps.
Step 5: Configure the RustDesk Client
- Download and install the official RustDesk client on your workstation.
- Open RustDesk and click the three vertical dots next to your ID → Network / ID/Relay Server.
- Enter your server details:
- ID Server:
remote.yourdomain.com - Relay Server:
remote.yourdomain.com - Key: [Paste your id_ed25519.pub string here]
- ID Server:
- Click Apply. You should see a green "Ready" status in the bottom footer.
rustdesk-host=remote.yourdomain.com,key=YOUR_KEY.exe) so that users on your network automatically connect to your private server on launch without manual setup.
Conclusion
By hosting your own RustDesk relay, you have built a private, encrypted remote support pipeline that operates independently of third-party SaaS vendors. Your connection data is sovereign, fast, and completely under your control.
Frequently asked questions
What is RustDesk?
An open-source remote-desktop tool — a functional equivalent of TeamViewer or AnyDesk — that works fully self-hosted when you run your own ID and relay servers.
Why self-host instead of using the public servers?
With your own server, connection metadata, sessions, and address-book identities stay on hardware you control, clients can reach your techs directly even if a vendor's cloud has an outage, and per-device licensing pricing stops applying to you.
What is the minimum to run a self-hosted RustDesk server?
One small Linux VPS with the hbbs (ID) and hbcmr (relay) services plus open ports, a client pointing at your address, and two-factor access. The install is a single Docker Compose file on most hosts.