feat(rustdesk): onboard self-hosted RustDesk server on hk2
Deploy hbbs + hbbr via a safe-by-default Ansible role (playbooks/rustdesk.yml): with rustdesk_confirm=false it only reports whether compose.yml matches live state and refuses to recreate the stack; with rustdesk_confirm=true it deploys and recreates. The relay assert rejects the known-bad hk2.wsvc.info hostname. Add health profiles rustdesk (hbbs/hbbr health, relay DNS) and hk2aux (co-located traefik/adguard/remark42 on hk2), plus the rustdesk-health runbook and AGENTS.md entry. Server image pinned rustdesk/rustdesk-server:1.1.14.
This commit is contained in:
@@ -0,0 +1,80 @@
|
||||
# RustDesk server health (hk2)
|
||||
|
||||
Read-only checks for the `/opt/rustdesk` stack on **hk2.chans.xyz**.
|
||||
|
||||
Facts: [hosts/hk2.chans.xyz.md](../hosts/hk2.chans.xyz.md)
|
||||
|
||||
Prefer the Ansible health report for routine checks and the
|
||||
[rustdesk playbook](../ansible/playbooks/rustdesk.yml) for reviewed config
|
||||
changes. Keep the SSH commands below for focused diagnosis.
|
||||
|
||||
## Focused SSH diagnostics
|
||||
|
||||
Use these only after the Ansible health report needs investigation.
|
||||
|
||||
### Quick remote
|
||||
|
||||
```bash
|
||||
ssh -4 windy@hk2.chans.xyz 'cd /opt/rustdesk && docker compose ps -a'
|
||||
```
|
||||
|
||||
Expect `hbbs` and `hbbr` both `Up`. Ignore any stopped orphans unless cleaning up.
|
||||
|
||||
### Version / image pin
|
||||
|
||||
Expect `rustdesk/rustdesk-server:1.1.14` (or the documented pin). Startup logs
|
||||
should show the relay list and no errors.
|
||||
|
||||
```bash
|
||||
ssh -4 windy@hk2.chans.xyz 'docker inspect hbbs --format "{{.Config.Image}}"; docker inspect hbbr --format "{{.Config.Image}}"'
|
||||
```
|
||||
|
||||
### Relay address (the critical check)
|
||||
|
||||
The `hbbs -r <host>:21117` value is advertised to every client as the relay
|
||||
(hbbr) address. It **must resolve to this host's public IP** `154.36.174.161`.
|
||||
`hk2.chans.xyz` is the correct value; `hk2.wsvc.info` has no DNS record and must
|
||||
never be used.
|
||||
|
||||
```bash
|
||||
# The value hbbs is actually serving (definitive):
|
||||
ssh -4 windy@hk2.chans.xyz 'docker inspect hbbs --format "{{json .Config.Cmd}}"'
|
||||
# expect ["hbbs","-r","hk2.chans.xyz:21117"]
|
||||
|
||||
# Confirm the relay hostname resolves to the public IP:
|
||||
dig +short hk2.chans.xyz A @1.1.1.1 # expect 154.36.174.161
|
||||
|
||||
# Confirm the relay hostname is what hbbs logs as its relay list:
|
||||
ssh -4 windy@hk2.chans.xyz 'docker logs hbbs 2>&1 | grep "relay-servers" | tail -1'
|
||||
# expect relay-servers=["hk2.chans.xyz:21117"]
|
||||
```
|
||||
|
||||
### Ports (from laptop / WSL)
|
||||
|
||||
```bash
|
||||
IP=154.36.174.161
|
||||
nc -vz -w 5 $IP 21117 # hbbr relay TCP
|
||||
nc -vz -w 5 $IP 21116 # hbbs rendezvous TCP
|
||||
nc -vz -u -w 5 $IP 21116 # hbbs rendezvous UDP
|
||||
nc -vz -w 5 $IP 21115 # hbbs NAT type test
|
||||
```
|
||||
|
||||
## Scheduled local check
|
||||
|
||||
The sanitized Ansible health profile is `rustdesk` (deployed via
|
||||
`ansible/playbooks/healthchecks.yml` on hosts whose inventory lists it). It runs
|
||||
locally through `vps-healthcheck.timer`, writes a sanitized JSON result to
|
||||
`/var/lib/vps-health/latest.json`, and never exposes secrets.
|
||||
|
||||
## After config changes
|
||||
|
||||
Reviewed changes to `/opt/rustdesk/compose.yml` (relay address, image pin, port
|
||||
mapping) are applied through the gated rustdesk playbook:
|
||||
|
||||
```bash
|
||||
cd ansible
|
||||
ansible-playbook playbooks/rustdesk.yml --limit rustdesk \
|
||||
-e '{"rustdesk_confirm": true}'
|
||||
```
|
||||
|
||||
Re-run the health report afterwards.
|
||||
Reference in New Issue
Block a user