RustDesk
Open-source remote desktop you host yourself
What is RustDesk?
RustDesk is an open-source remote desktop application that works out of the box, but also lets you run your own relay and rendezvous server. Self-hosting the server gives you a private remote access setup with no third-party in the middle.
Best for
Anyone needing remote desktop without trusting a commercial relay
Why choose RustDesk
RustDesk is the rare remote desktop tool that lets you own the part that usually belongs to someone else. The client works out of the box like any commercial product, but the relay and rendezvous servers are open source and self-hostable, which means the connection between you and the machine you are reaching goes through infrastructure you control. That removes the third party that can see your sessions, change the terms, or start charging, and it is the strongest argument for it over the commercial alternatives. It supports the platforms you would expect, transfers files, and works on modest hardware. For anyone who needs remote access to their own machines and objects to trusting a commercial relay, self-hosting the server is the whole point.
Replaces
- TeamViewer
- AnyDesk
- Chrome Remote Desktop
Key features
- Cross-platform client
- Self-hosted relay server option
- File transfer and clipboard sync
- End-to-end encryption
What to watch out for
The server component is what makes this worthwhile and it is also the part that requires effort: you need a host with a public address, correct firewall rules, TLS certificates and a client configuration that points at your server rather than the public one. Misconfigure it and clients silently fall back to the public relays, which defeats the purpose without telling you. Remote desktop by definition grants control of a machine, so the security of the relay, the keys and the client authentication is the security of everything reachable from that machine. Platform support varies in polish, and some features lag the commercial products. On a home network, exposing RDP or VNC directly is a mistake; going through a relay with proper authentication is the correct shape.
How to deploy
- Docker
- Binary
Getting started
Set up the server on a host with a stable public address, configure TLS properly, and confirm clients are actually using it rather than falling back to the public relays. Choose keys deliberately and keep them private, because they are what authenticate your clients to your server. Enable the appropriate client settings so unattended access requires a strong password, and restrict which machines are allowed to connect. Test from outside your network, because a configuration that works on the LAN can fail entirely across the internet. Keep the server patched, since it is publicly reachable by design and therefore a target.
Typical setup
The server runs on a host with a stable public address, TLS configured properly, and firewall rules that permit only the ports it needs. Clients are configured to point at that server, and the configuration is verified to actually be in effect — a silent fallback to the public relays defeats the entire purpose without any visible error. Keys are chosen deliberately and kept private, since they authenticate clients to the server. Unattended access requires a strong password and is restricted to specific machines. Connectivity is tested from outside the network, and the server is patched regularly because it is publicly reachable by design.
Who should look elsewhere
Do not self-host the server if you are not prepared to run a public service with TLS, patching and access control, because a misconfigured remote access server is worse than a commercial tool you do not control. Avoid it if the platform you need is only well supported by a commercial product, since fighting a weak client is not worth the principle. And if your remote access need is occasional within your own network, a VPN into the LAN is both simpler and safer than exposing a relay.
Project health
- GitHub stars: 124,892
- Last code push: 2026-09-30
- Open issues: 166
- Status: actively developed
Figures pulled from the GitHub API and refreshed periodically.