Child of #682. Venue: cloud-seven. A permanent Windows machine on the venue LAN acting as the Tesira gateway, so Tesira read/edit/control can be done remotely from now on WITHOUT a technician on site for every change.
Why this is its own thing
Two other tickets are adjacent but different:
- #693 is the one-off technician visit for the physical crackle (and opportunistic config fixes).
- #682 is the control software (hydrabiamp central + Turbo worker + TTP).
This ticket is the HOST both of those depend on going forward: a stable, always-on Windows box inside the network. Windows is non-negotiable because Biamp's Tesira software (the only way to read/edit/push the .tmf design) is Windows-only; a permanent Windows box on the LAN means design changes become a remote-desktop session, not a site visit.
What it does (one box, several jobs)
- Runs Biamp Tesira software for design retrieve / edit / push (GUI, over remote desktop).
- Hosts the hydrabiamp Turbo worker (headless TTP control + audit; any OS, but co-locating is fine).
- Can also host the hydraroar venue relay (#550) so the Sonos side stops depending on the CLI fallback. One gateway, three roles.
Requirements
- Small always-on Windows box (mini-PC/NUC) or a Windows VM, on the venue LAN with reach to the AV segment and the Tesira main (11.0.0.201).
- Interactive remote access into a real desktop session: RDP over the WireGuard mesh, or AnyDesk. NOTE the lesson from 2026-09-10: our exec channel runs in session 0 and cannot drive GUI apps (macOS TCC / Windows session isolation), so the gateway must be reachable as an interactive session, not just exec.
- Enrolled so we manage/patch it; TTP enabled on the Tesira so the Turbo worker has its channel.
Interim vs permanent
Near term, chunky-turnip-23 (Windows dev box, same LAN) is the machine for the FIRST design recovery (see #682). It is NOT the permanent gateway: it is a dev/test body that gets repurposed and wiped. This ticket is the durable replacement.
Security note
A permanent remote-access Windows box on the venue LAN is a security-posture item, relevant to the Secure Inside handover and the security as-built (#575). Decide remote-access method and hardening as part of that.