NixOS XRDP Guide: RDP Remote Desktop Access on AWS (Base NixOS 25.05)¶
The Base NixOS 25.05 AMI ships with XRDP and KDE Plasma support built in. Most people never turn it on: they SSH in, find no desktop, and conclude NixOS on AWS is terminal-only.
It isn't. A full graphical desktop over RDP takes one uncommented line, one rebuild, and one password — about five minutes end to end.
This is the complete NixOS XRDP walkthrough for EC2: enabling the server declaratively, setting the password RDP requires, and connecting from your machine.
Prerequisites¶
Before starting:
- An EC2 instance running the Base NixOS 25.05 AMI — new to the AMI? The setup guide covers subscription through first login
- Your EC2 key pair (ECDSA recommended; RSA is deprecated on modern NixOS)
- An RDP client on your local machine (Windows, macOS, and Linux all ship one)
That's the whole list.
Step 1: Connect via SSH¶
Setup happens over SSH. The default user is ec2-user:
Use the ECDSA key, not RSA.
Step 2: Enable XRDP in configuration.nix¶
Everything on a NixOS system is declared in one file — the desktop included. The AMI ships an xrdp.nix module with XRDP and KDE Plasma pre-configured, switched off by default.
Open the configuration:
Find the commented import of /etc/nixos/xrdp.nix and uncomment it. That single line pulls in the entire XRDP + KDE Plasma stack.
No package hunting. No display-manager wiring. The module already exists; you're switching it on.
Step 3: Rebuild, Then Set a Password¶
Apply the change:
NixOS builds the new system configuration and switches to it atomically. On some systems the first rebuild needs to run twice before XRDP comes up cleanly — if nothing responds after the first pass, run it again.
Now give ec2-user a password. RDP authenticates with a username and password, unlike SSH, which stays key-only:
Pick something long. This password plus your security group is all that stands between the internet and your desktop.
Step 4: Open RDP in the Security Group and Connect¶
Your instance's security group needs an inbound rule allowing RDP from your IP.
With the rule in place: open your RDP client, enter the instance's public IP, and log in as ec2-user with the password from Step 3.
You'll land in a KDE Plasma session — a full desktop environment running on your EC2 instance.
When It Doesn't Work¶
Two known failure modes, both cheap to fix:
- XRDP doesn't respond after the first rebuild. Run
sudo nixos-rebuild switcha second time. That's documented behavior on some systems, not something you did wrong. - Connection refused or timeout. Almost always the Step 4 security-group rule. Check it allows RDP from your current IP.
And because this is NixOS, a bad experiment costs nothing:
One command returns the machine to exactly its previous configuration. XRDP off, nothing left behind.
Why Declarative Remote Desktop Matters¶
On a traditional distro, adding remote desktop means picking a display manager, installing an RDP or VNC server, reconciling their configs, and hoping the next upgrade doesn't break the pairing. Here, the desktop is one line in one file. Rebuild another instance with the same configuration.nix and you get the identical desktop, every time.
That's the practical difference between configured and declared: your remote-desktop setup survives reboots, reproduces across instances, and rolls back atomically. For teams running GUI tooling on cloud instances — browser-based testing, IDEs, graphical clients — that predictability is the point.
For the rest of the NixOS-on-AWS surface (SSH details, package updates, version upgrades), see the NixOS reference doc. And if you're still weighing NixOS against Ubuntu or Amazon Linux, NixOS vs Traditional Linux on AWS covers the five structural reasons teams switch.
Launch It¶
The Base NixOS 25.05 AMI includes the XRDP + KDE Plasma module out of the box — this guide is just switching it on. Launch it in your AWS account and you're one rebuild away from a desktop.