HydraIssues

cosmic-pretzel-98: Windows firewall popup blocks first-peer Sunshine connection
done bug Project: hydrabody Reporter: cederik 29 Apr 2026 19:52

Description

Hit on 2026-04-29 while validating cross-venue-by-owner streaming: kicked off a rupelmonde-castle-viewer stream from cheeky-cactus-86 (bxl1/ad6, visit.flanders) targeting cosmic-pretzel-98 (bxl1/cloud-seven, visit.flanders, WG 10.10.100.12).

Stream pairing succeeded, Moonlight subprocess launched, status flipped idle → pairing → streaming. But on the Windows side a firewall prompt blocked something on cosmic-pretzel-98's display that operators with remote access could not dismiss. Stream had to be killed from the kiosk side (pkill -9 -f 'HydraExperienceNet stream' && pkill -9 -f Moonlight).

Likely cause: cheeky-cactus's WireGuard peer (10.10.100.11) is a new peer for cosmic-pretzel-98 — Windows Defender prompts whenever a new application or peer initiates a connection.

Fix options (pick one or combine):

  1. Pre-add a permanent firewall rule during hydrabody provisioning that allows Sunshine's expected peer ranges (the WG mesh subnet 10.10.100.0/24 and the LAN body subnet) on the Sunshine ports (47984, 47989, 47990, 48010 UDP/TCP).
  2. Provision sunshine.exe in Program Files with a properly registered Windows Defender allow rule so it does not trigger user prompts.
  3. Disable Windows Defender prompts at provisioning time for this kiosk role (least preferred, lower default trust).

Recommend (1) — explicit allow rule scoped to the WG mesh + Sunshine ports. The rule should be idempotent and survive Windows updates.

Repro:

  • Kiosk at any visit.flanders venue without a body (e.g. cheeky at ad6) requests an experience that resolves to a body the kiosk has never paired with before.
  • Body shows a firewall popup; stream subprocess does not produce video on the kiosk display.
  • Workaround: physically dismiss popup, OR pkill the stream and have an admin RDP/shell to the body to allow the rule once.

Repos: hydrabody (provisioning step), possibly hydracluster recipe (recipes/hydrabody-windows.yaml).

Related: issue #113 (cross-venue-by-owner) — this firewall behaviour will surface for every new cross-venue pairing in production until baked-in rules exist.

Comments (1)

api 29 Apr 2026 21:47

Resolved end-to-end. Two fixes were needed for cross-venue streaming to work:

  1. Cosmic-pretzel firewall popup (the original symptom): set the WireGuard interface profile to Private (Set-NetConnectionProfile -InterfaceAlias hydraguard-air -NetworkCategory Private) and disabled NotifyOnListen for the Public profile. Both persisted across reboot.

  2. Cross-venue UDP packet loss (uncovered while verifying #1): pre-v2.0.32, pkg/client/moonlight.go invoked Moonlight with hardcoded --bitrate 150000 (150 Mbps), saturating the consumer-ISP uplink that backs hydraguard-air at ad6. Moonlight log showed Unrecoverable frame N: 21 received < 110 needed across thousands of frames. Fixed in v2.0.32 by making the bitrate adaptive: 150 Mbps for LAN hosts, 25 Mbps for any host inside the 10.10.0.0/16 WG range.

Verified end-to-end 2026-04-29: cheeky-cactus (bxl1/ad6) streamed rupelmonde-castle-viewer from cosmic-pretzel-98 (bxl1/cloud-seven, same-owner cross-venue path) with Rupelmonde rendering correctly on cheeky after the bitrate change.