Child of #714, feeds #705. In hydrahyperscaler: scripts/reflector/cloud-init.yaml (installs hydraprobe from releases.experiencenet.com, writes the HMAC key, systemd unit hydraprobe-server on UDP 2112 with server min-interval 0, WireGuard installed but unpeered) plus per-provider launch snippets for AWS t3.micro, Azure B1s, GCP e2-micro. One variable block per region: name, provider, region, instance type. Peering at the hub stays a manual HydraGuard step per the campaign runbook.