HydraIssues

AD6 transition to pure consumer network: drop router API monitoring
closed improvement Project: hydraneck Reporter: cederik 29 Apr 2026 19:50

Description

Background

AD6 currently runs an Omada controller (omada-ad6 at https://127.0.0.1:8043, reachable to hydraneck through a tunnel) and hydraneck scans it for DHCP leases, body correlation, and bandwidth. The scan results power the venue dashboard at https://hydraneck.experiencenet.com/admin/venues/ad6.

The plan for AD6 changes: it becomes a pure consumer network with no API-accessible router. Hydraneck should assume no API information from AD6 going forward.

Decision

Once the consumer-network transition happens at AD6:

  1. Remove the omada-ad6 block from ~/.hydraneck/config.yaml under routers.ad6.
  2. Delete the corresponding secret with key ad6/omada-ad6 from the secrets store (web UI at /admin/secrets, or curl -X DELETE /admin/api/secrets/ad6/omada-ad6).
  3. Leave the AD6 venue itself in hydravenues — body assignment, district info, and bandwidth budgeting still apply. The scanner will simply report 0 routers for AD6 (matching cloud-seven and rupelmonde before Citymesh delivers).

Hydraneck handles "venue without router" cleanly already; no code change needed for the transition itself.

Open questions

  • Body discovery and correlation: today the omada DHCP lease list lets hydraneck cross-reference body IPs with cluster nodes, producing the agent-down / not-on-network diagnoses on the venue page. Without an API on the venue router, what do we want hydraneck to show for AD6 bodies? Options: (a) just "no network visibility" status, (b) infer reachability from hydracluster's own connectivity check, (c) accept the loss of router-side correlation and rely on body self-reporting.
  • Streaming debug: the live-tail capability planned in Phase 4-5 of issue #115 (binary-API torch / log follow) won't work at AD6 once it loses API access. AD6-side stream issues will need to be debugged from hydracluster + body logs alone.
  • Timing: when does the transition happen? The issue should be parked and re-opened when the AD6 cutover date is set.

Out of scope

  • Other venues. cloud-seven and rupelmonde get MikroTik routers with full API access (managed by Citymesh, RB5009UG+S+IN). The mobile kit also has write access. AD6 is the only venue moving to pure consumer.
  • Hydraneck code changes. The current code already treats venues without routers as a normal case (routers: [] in scan results, dashboard shows the venue without a "Routers" section). No new code is needed for the transition; the work is purely a config edit + secret deletion at the scheduled cutover.

Action items at cutover

  • Edit /root/.hydraneck/config.yaml and remove the omada-ad6 entry under routers.ad6.
  • curl -X DELETE -H "Authorization: Bearer $ADMIN" https://hydraneck.experiencenet.com/admin/api/secrets/ad6/omada-ad6
  • systemctl restart hydraneck
  • Confirm Scan ad6: 0 routers, ... in the journal.
  • Update venue page expectations with stakeholders: AD6 bodies show "no network visibility" status going forward.