New to hosting? Start with the step-by-step install guide.
A production-ready Docker image for hosting Rust dedicated servers with optional Oxide/uMod modding support.
- Easy Setup: Run a Rust server with a single
docker compose up -d - Automatic Updates: Server files update automatically on container start
- Oxide/uMod Support: Built-in support for the Oxide modding framework
- Automated Backups: Configurable backup system with retention policies
- RCON Support: Remote console access via RCON and WebRCON
- Highly Configurable: 40+ environment variables for customization
- Health Monitoring: Built-in health checks for container orchestration
- CI/CD Ready: Full E2E test suite with GitHub Actions
The image is published to Docker Hub, so there is nothing to clone or build.
-
Create a
docker-compose.yml:services: rust-server: image: abspwgm/absolute-rust-server:latest container_name: rust-server restart: unless-stopped ports: - "28015:28015/udp" # Game port - "27015:27015/udp" # Query port (server list) - "127.0.0.1:28016:28016/tcp" # RCON (admin, keep private) - "127.0.0.1:28017:28017/tcp" # WebRCON (admin, keep private) volumes: - rust-server:/opt/rust/server - rust-config:/config environment: - SERVER_NAME=My Rust Server - ENABLE_OXIDE=false volumes: rust-server: rust-config:
-
Start the server:
docker compose up -d
-
View logs:
docker logs -f rust-server
The first start downloads the Rust server files (allow 10GB+ of disk), which can take 30-40 minutes. See Environment Variables for everything you can set, and Building from Source if you would rather build the image yourself.
docker run -d \
--name rust-server \
-p 28015:28015/udp \
-p 27015:27015/udp \
-p 127.0.0.1:28016:28016/tcp \
-p 127.0.0.1:28017:28017/tcp \
-v rust-server:/opt/rust/server \
-v rust-config:/config \
-e SERVER_NAME="My Rust Server" \
-e ENABLE_OXIDE=true \
abspwgm/absolute-rust-server:latest| Port | Protocol | Description |
|---|---|---|
| 28015 | UDP | Game port (player connections) |
| 27015 | UDP | Steam query port (server list) |
| 28016 | TCP | RCON port (admin, bound to localhost by default) |
| 28017 | TCP | WebRCON port (admin, bound to localhost by default) |
| Variable | Default | Description |
|---|---|---|
SERVER_NAME |
Rust Server |
Server name shown in browser |
SERVER_PORT |
28015 |
Game port |
SERVER_IDENTITY |
rust_server |
Server identity (folder name for saves) |
SERVER_SEED |
Random | World seed (leave empty for random) |
SERVER_WORLDSIZE |
4000 |
World size (1000-6000) |
SERVER_MAXPLAYERS |
50 |
Maximum players |
SERVER_LEVEL |
Procedural Map |
Map type |
SERVER_DESCRIPTION |
Empty | Server description |
SERVER_URL |
Empty | Server website URL |
SERVER_HEADERIMAGE |
Empty | Server header image URL |
SERVER_SAVEINTERVAL |
600 |
Auto-save interval in seconds |
| Variable | Default | Description |
|---|---|---|
RCON_ENABLED |
true |
Enable RCON |
RCON_PORT |
28016 |
RCON port |
RCON_PASSWORD |
Empty | RCON password (empty or a known default = one is generated, see RCON Access) |
RCON_WEB |
true |
Enable WebRCON |
RCON_WEB_PORT |
28017 |
WebRCON port |
| Variable | Default | Description |
|---|---|---|
ENABLE_OXIDE |
false |
Enable Oxide/uMod installation |
OXIDE_AUTO_UPDATE |
true |
Install a newer pinned Oxide version on start |
OXIDE_VERSION |
2.0.7723 |
Oxide release to install |
OXIDE_SHA256 |
(pinned) | Checksum the download must match |
| Variable | Default | Description |
|---|---|---|
UPDATE_ON_START |
true |
Update server on container start |
UPDATE_IF_IDLE |
true |
Only update when no players online |
UPDATE_CRON |
Empty | Cron schedule for updates |
UPDATE_TIMEOUT |
1800 |
Update timeout in seconds |
| Variable | Default | Description |
|---|---|---|
BACKUPS_ENABLED |
true |
Enable automatic backups |
BACKUPS_CRON |
0 */6 * * * |
Backup schedule (every 6 hours) |
BACKUPS_MAX_AGE |
7 |
Delete backups older than N days |
BACKUPS_MAX_COUNT |
0 |
Keep only N backups (0 = unlimited) |
BACKUPS_IF_IDLE |
false |
Only backup when no players online |
BACKUPS_COMPRESSION |
zip |
Compression type (zip or tar.gz) |
| Variable | Default | Description |
|---|---|---|
PUID |
1000 |
User ID for file permissions |
PGID |
1000 |
Group ID for file permissions |
TZ |
UTC |
Timezone |
CUSTOM_ARGS |
Empty | Additional server arguments |
| Path | Description |
|---|---|
/opt/rust/server |
Server files (persisted for caching) |
/config |
Configuration, saves, and backups |
Set ENABLE_OXIDE=true in your environment:
environment:
- ENABLE_OXIDE=true
- OXIDE_AUTO_UPDATE=trueOxide is a mod loader, so it runs arbitrary code next to your world. It is never
baked into the image: the container downloads the exact release named by
OXIDE_VERSION and refuses to install it unless the archive matches
OXIDE_SHA256. Both are pinned in the image and bumped together in a PR, so an
upstream release (or a tampered download) can never reach your server on its own.
OXIDE_AUTO_UPDATE=true means "move to the pinned version if a different one is
installed", not "fetch whatever is newest".
- Plugins are stored in
/config/oxide/plugins/inside the container - Place
.csplugin files in this directory - Restart the server or use RCON to reload
With Docker Compose volumes:
# Copy a plugin to the server
docker cp MyPlugin.cs rust-server:/opt/rust/server/oxide/plugins/Plugin configurations are stored in /opt/rust/server/oxide/config/
docker exec rust-server /opt/rust/scripts/rust-backup --force- Stop the server
- Extract backup to the appropriate directories
- Start the server
docker compose stop
# Extract backup...
docker compose startBackups are stored in /config/backups/ with timestamps:
rust_20260130_120000.zip
RCON is a remote admin console: anyone who can reach it with the password controls the server. Two defaults keep it safe.
If RCON is enabled and RCON_PASSWORD is empty or a known default (changeme, password, your_secure_password, admin, rcon), the container generates a strong random password on start and saves it to /config/rcon_password (mode 600, owned by the server user). The value is never written to the logs. Read it with:
docker exec rust-server cat /config/rcon_passwordThe generated password is kept across restarts. To choose your own, set RCON_PASSWORD to anything not on the list above; it is used unchanged and no file is written. With the repository's docker-compose.yml you can do that without editing the file:
RCON_PASSWORD='something-long-and-unique' docker compose up -ddocker-compose.yml binds RCON (28016/tcp) and WebRCON (28017/tcp) to 127.0.0.1, so they are only reachable from the Docker host. The game (28015/udp) and query (27015/udp) ports stay public. To administer the server from another machine, prefer an SSH tunnel over exposing the ports:
ssh -L 28016:127.0.0.1:28016 user@your-serverOnly change the bindings to 28016:28016/tcp if you have set a strong password and restricted access with a firewall. Never forward these ports on your router.
Connect to localhost:28016 on the Docker host (or through the tunnel) with your RCON password.
WebRCON listens on port 28017 (if enabled); point a WebRCON client at localhost:28017.
status # Show server status
players # List connected players
say "message" # Broadcast message
save # Force save
oxide.version # Check Oxide version
oxide.reload * # Reload all plugins
- Check logs:
docker logs rust-server - Verify ports are available
- Ensure sufficient disk space (10GB+)
- Check memory (4GB+ recommended)
- Verify ports are forwarded: 28015/udp, 27015/udp (RCON ports should not be forwarded)
- Check firewall rules
- Verify server is fully started (check logs for "Server startup complete")
- Verify
ENABLE_OXIDE=trueis set - Check logs for Oxide-related errors
- Try forcing reinstall:
docker exec rust-server /opt/rust/scripts/oxide-installer --install --force
- Reduce world size:
SERVER_WORLDSIZE=3000 - Increase container memory limits
- Use SSD storage for volumes
The repository's docker-compose.yml builds the image locally instead of pulling it:
git clone https://github.com/abspwgm/absolute-rust-server.git
cd absolute-rust-server
docker compose up -d --buildOr build the image on its own:
docker build -t absolute-rust-server:latest ../tests/run_e2e.shThis project is licensed under the Apache License 2.0 - see the LICENSE file for details.
Contributions are welcome! Please feel free to submit a Pull Request.
- Facepunch Studios for Rust
- uMod/Oxide for the modding framework
- Valve for SteamCMD