feat(rustdesk): onboard self-hosted RustDesk server on hk2

Deploy hbbs + hbbr via a safe-by-default Ansible role (playbooks/rustdesk.yml):
with rustdesk_confirm=false it only reports whether compose.yml matches live
state and refuses to recreate the stack; with rustdesk_confirm=true it deploys
and recreates. The relay assert rejects the known-bad hk2.wsvc.info hostname.

Add health profiles rustdesk (hbbs/hbbr health, relay DNS) and hk2aux (co-located
traefik/adguard/remark42 on hk2), plus the rustdesk-health runbook and AGENTS.md
entry. Server image pinned rustdesk/rustdesk-server:1.1.14.
This commit is contained in:
windyboy
2026-08-12 21:16:30 +08:00
parent e7296e664a
commit 035587e3bf
8 changed files with 320 additions and 0 deletions
+80
View File
@@ -0,0 +1,80 @@
# RustDesk server health (hk2)
Read-only checks for the `/opt/rustdesk` stack on **hk2.chans.xyz**.
Facts: [hosts/hk2.chans.xyz.md](../hosts/hk2.chans.xyz.md)
Prefer the Ansible health report for routine checks and the
[rustdesk playbook](../ansible/playbooks/rustdesk.yml) for reviewed config
changes. Keep the SSH commands below for focused diagnosis.
## Focused SSH diagnostics
Use these only after the Ansible health report needs investigation.
### Quick remote
```bash
ssh -4 windy@hk2.chans.xyz 'cd /opt/rustdesk && docker compose ps -a'
```
Expect `hbbs` and `hbbr` both `Up`. Ignore any stopped orphans unless cleaning up.
### Version / image pin
Expect `rustdesk/rustdesk-server:1.1.14` (or the documented pin). Startup logs
should show the relay list and no errors.
```bash
ssh -4 windy@hk2.chans.xyz 'docker inspect hbbs --format "{{.Config.Image}}"; docker inspect hbbr --format "{{.Config.Image}}"'
```
### Relay address (the critical check)
The `hbbs -r <host>:21117` value is advertised to every client as the relay
(hbbr) address. It **must resolve to this host's public IP** `154.36.174.161`.
`hk2.chans.xyz` is the correct value; `hk2.wsvc.info` has no DNS record and must
never be used.
```bash
# The value hbbs is actually serving (definitive):
ssh -4 windy@hk2.chans.xyz 'docker inspect hbbs --format "{{json .Config.Cmd}}"'
# expect ["hbbs","-r","hk2.chans.xyz:21117"]
# Confirm the relay hostname resolves to the public IP:
dig +short hk2.chans.xyz A @1.1.1.1 # expect 154.36.174.161
# Confirm the relay hostname is what hbbs logs as its relay list:
ssh -4 windy@hk2.chans.xyz 'docker logs hbbs 2>&1 | grep "relay-servers" | tail -1'
# expect relay-servers=["hk2.chans.xyz:21117"]
```
### Ports (from laptop / WSL)
```bash
IP=154.36.174.161
nc -vz -w 5 $IP 21117 # hbbr relay TCP
nc -vz -w 5 $IP 21116 # hbbs rendezvous TCP
nc -vz -u -w 5 $IP 21116 # hbbs rendezvous UDP
nc -vz -w 5 $IP 21115 # hbbs NAT type test
```
## Scheduled local check
The sanitized Ansible health profile is `rustdesk` (deployed via
`ansible/playbooks/healthchecks.yml` on hosts whose inventory lists it). It runs
locally through `vps-healthcheck.timer`, writes a sanitized JSON result to
`/var/lib/vps-health/latest.json`, and never exposes secrets.
## After config changes
Reviewed changes to `/opt/rustdesk/compose.yml` (relay address, image pin, port
mapping) are applied through the gated rustdesk playbook:
```bash
cd ansible
ansible-playbook playbooks/rustdesk.yml --limit rustdesk \
-e '{"rustdesk_confirm": true}'
```
Re-run the health report afterwards.