Remote Access

Self-Hosted Remote Desktop (RustDesk)

Run your own RustDesk ID and relay services, with control over client configuration, network access and service recovery.

Host the RustDesk ID and relay services on your own offshore VPS. Clients can connect directly when network conditions allow, or use the configured relay. Configure each client with your server details and verify the connection mode and security before relying on remote access.

What you get

  • Your own ID and relay services, with clients configured to use them
  • End-to-end encrypted, with clients pinned to your server’s public key
  • Desktop clients, with features and licensing checked for the edition you use
  • Light: about 512 MB of memory and 2 GB of disk

Get it running

Pick a VPS with good connectivity

Resources are modest, but this is a relay: what matters is bandwidth and latency between you and the machines you connect to. Choose an offshore VPS in a sensible location for both ends.

Install it in one click

Install RustDesk from the catalog. It runs the relay and ID services rather than a website, so there is no hostname or certificate step. See how one-click installs work.

Point your clients at your server

Configure each RustDesk client with your server address and its public key. The key is what stops a client from being tricked into using someone else’s relay, so treat it as part of the setup rather than an optional field.

Set strong access on every endpoint

Give each machine a permanent password you generated, rather than relying on the short rotating code, and only where unattended access is genuinely needed.

This one uses several raw ports, so no onion and no certificate

RustDesk uses TCP and UDP ports for its ID, relay and connection services. This catalog deployment does not use the web-app hostname, HTTPS certificate or Tor mirror flow. Check the ports required by your configuration and expose only those needed.

Unattended access is a permanent door

A machine with a saved permanent password can be reached by anyone who has that password, at any time, with no one present to approve it. Use long generated passwords, set them per machine rather than reusing one, and remove access when a device is retired.

Why self-hosting matters here

Running the relay yourself gives you control over that part of the connection path. Protect both endpoints, verify the client configuration and limit unattended access; hosting the relay does not secure a compromised client device.

Recover the service and reconnect clients

For a supported deployment with the Impreza Agent online, use app inspection and maintenance, then test an actual client connection. Check direct and relay paths where applicable; a running container alone does not confirm that the required network ports are reachable.

Review app backups to Impreza S3 for the service configuration and persistent server key material. Protect private keys and verify the public key expected by clients after recovery. A server backup does not include files or settings on remote desktop endpoints.

For migration between compatible servers, review firewall rules, server address and client settings before switching users. Retain an independent way to administer the host while testing remote access.

Start now

Spin up an offshore VPS and install RustDesk from the catalog, or read the documentation.

Ready to build privacy-first?

No KYC, no email required, crypto payment. Deploy an offshore server in minutes, or do it all by chat with the Impreza agent.