Give each Pi its own WireGuard tunnel, and address scales by mesh address
closedimprovementProject: hydraguardReporter: 5 Aug 2026 16:54
Comments (1)
api12 Aug 2026 12:47
Done and deployed. All 3 Pis terminate their own hydraguard-air tunnels (10.10.100.17/19/18) and scales are addressed by mesh address — verified surviving repeated LAN moves. The AllowedIPs /8 collision fix landed in code for both air.go and headipad.go (narrowed to 10.10.0.0/16). hydraguard v2.4.0 deployed to the district hub WITHOUT restarting serve (wg0 undisturbed, 26 peers stayed up); verified the config generator now emits 'AllowedIPs = 10.10.0.0/16' via air config on an existing peer. The 3 live spokes were already hand-fixed to /16. Closing.
Done and deployed. All 3 Pis terminate their own hydraguard-air tunnels (10.10.100.17/19/18) and scales are addressed by mesh address — verified surviving repeated LAN moves. The AllowedIPs /8 collision fix landed in code for both air.go and headipad.go (narrowed to 10.10.0.0/16). hydraguard v2.4.0 deployed to the district hub WITHOUT restarting serve (wg0 undisturbed, 26 peers stayed up); verified the config generator now emits 'AllowedIPs = 10.10.0.0/16' via
air configon an existing peer. The 3 live spokes were already hand-fixed to /16. Closing.