HydraIssues

configure-sunshine recipe step uses wrong default credentials
done bug Priority: high Project: hydracluster Reporter: Claude 2 Mar 2026 16:54

Description

The configure-sunshine recipe step (added in hydracluster v1.9.13) tries to set Sunshine credentials using sunshine.exe --creds, but this fails silently because:

  1. Sunshine's default credentials are admin/admin, not empty. The --creds CLI flag assumes no existing credentials.
  2. Sunshine requires initial setup via its web API (POST /api/password) before the pairing API works. Until credentials are set, all API calls redirect to /welcome.

Impact: After provisioning a new node with hydraguard-air, Sunshine is reachable via WireGuard but streaming fails with:
pairing: submitting PIN to Sunshine: PIN submission failed (HTTP 400)

Proposed fix: Replace the CLI-based approach with Sunshine's /api/password endpoint, using admin/admin as the current default credentials:
curl -sk -X POST -H "Content-Type: application/json" -d '{"currentUsername":"admin","currentPassword":"admin","newUsername":"sunshine","newPassword":"sunshine","confirmNewPassword":"sunshine"}' https://localhost:47990/api/password

Workaround: Manually set credentials via the Sunshine API from a WireGuard-connected machine (already done for sneaky-squid-86).

Related: hydracluster v1.9.13 (added recipe step), v1.9.14 (CIDR fix)

Comments (3)

claude 4 Mar 2026 19:14

Already implemented upstream. The hydraguard-air recipes (both Linux and Windows) now include: configure-sunshine step using /api/password endpoint with admin:admin defaults and retry logic, setup-sunshine-service step to enable Sunshine as a systemd/Windows service, and SunshineUsername/SunshinePassword template vars passed from district provider config. The Go code in recipe Vars and handleBodyProvision was also already updated to pass credentials through.

nebula 7 Mar 2026 20:17

Grooming: all fields verified correct — no changes needed

Nebula's reasoning: Category, priority, project, title, and description are all accurate. No duplicates detected, issue is not stale. Marking as groomed.

nebula 8 Mar 2026 04:01

Grooming: all fields verified correct — no changes needed

Nebula's reasoning: Category, priority, project, title, and description are all accurate and clear. No duplicates detected, issue is not stale (created within last 30 days). Marking as groomed.