Hit on 2026-04-29 while validating cross-venue-by-owner streaming: kicked off a rupelmonde-castle-viewer stream from cheeky-cactus-86 (bxl1/ad6, visit.flanders) targeting cosmic-pretzel-98 (bxl1/cloud-seven, visit.flanders, WG 10.10.100.12).
Stream pairing succeeded, Moonlight subprocess launched, status flipped idle → pairing → streaming. But on the Windows side a firewall prompt blocked something on cosmic-pretzel-98's display that operators with remote access could not dismiss. Stream had to be killed from the kiosk side (pkill -9 -f 'HydraExperienceNet stream' && pkill -9 -f Moonlight).
Likely cause: cheeky-cactus's WireGuard peer (10.10.100.11) is a new peer for cosmic-pretzel-98 — Windows Defender prompts whenever a new application or peer initiates a connection.
Fix options (pick one or combine):
hydrabody provisioning that allows Sunshine's expected peer ranges (the WG mesh subnet 10.10.100.0/24 and the LAN body subnet) on the Sunshine ports (47984, 47989, 47990, 48010 UDP/TCP).Program Files with a properly registered Windows Defender allow rule so it does not trigger user prompts.Recommend (1) — explicit allow rule scoped to the WG mesh + Sunshine ports. The rule should be idempotent and survive Windows updates.
Repro:
Repos: hydrabody (provisioning step), possibly hydracluster recipe (recipes/hydrabody-windows.yaml).
Related: issue #113 (cross-venue-by-owner) — this firewall behaviour will surface for every new cross-venue pairing in production until baked-in rules exist.
Resolved end-to-end. Two fixes were needed for cross-venue streaming to work:
Cosmic-pretzel firewall popup (the original symptom): set the WireGuard interface profile to Private (
Set-NetConnectionProfile -InterfaceAlias hydraguard-air -NetworkCategory Private) and disabledNotifyOnListenfor the Public profile. Both persisted across reboot.Cross-venue UDP packet loss (uncovered while verifying #1): pre-v2.0.32,
pkg/client/moonlight.goinvoked Moonlight with hardcoded--bitrate 150000(150 Mbps), saturating the consumer-ISP uplink that backs hydraguard-air at ad6. Moonlight log showedUnrecoverable frame N: 21 received < 110 neededacross thousands of frames. Fixed in v2.0.32 by making the bitrate adaptive: 150 Mbps for LAN hosts, 25 Mbps for any host inside the 10.10.0.0/16 WG range.Verified end-to-end 2026-04-29: cheeky-cactus (bxl1/ad6) streamed rupelmonde-castle-viewer from cosmic-pretzel-98 (bxl1/cloud-seven, same-owner cross-venue path) with Rupelmonde rendering correctly on cheeky after the bitrate change.