Set up Hydrascale
SkillFiles & storageRead the Hydrascale state on a host and report it, and print each command that changes the host. Use when asked to set up Hydrascale, to explain why a tailnet is down, or to change the configuration file.
Available today. Use it from your connected AI after setup.
No other account needed.
Connect ahel once, and every AI you use reads what you have installed.
Then ask your AI: use the Set up Hydrascale skill
What this skill tells your AI
The instructions your AI receives, as published by crank-git/hydrascale in skills/hydrascale-setup/SKILL.md and read by ahel’s review.
Hydrascale joins one Linux host to several tailnets. The daemon holds one namespace per
tailnet, and it drives the host toward the state that /etc/hydrascale/config.yaml
declares.
Warning — one command that changes the host disconnects every tailnet. Print such a command for the operator. Run none of them.
The commands you run
The allowed-tools block above names five Hydrascale commands. Each command reads the
state, and none of them changes the host.
| Command | Result |
|---|---|
hydrascale status | The desired state and the actual state of each tailnet. |
hydrascale list | The identifier of each tailnet in the configuration file. |
hydrascale diff | The difference between the desired state and the actual state. |
hydrascale env <id> | The environment values for the namespace of one tailnet. |
hydrascale version | The version of the binary. |
The daemon holds the control socket /var/lib/hydrascale/api.sock at mode 0600, so
hydrascale status needs sudo on a host that names no socket group.
Read the state in this order:
- Run
hydrascale version. It states the version that the host runs. - Run
hydrascale list. It reads the configuration file, so it names a tailnet that holds no namespace. - Run
hydrascale status. It names each tailnet that is down. - Run
hydrascale diff. It names each action that a reconciliation performs.
A tailnet needs about 20 seconds after a restart of the service before hydrascale status
reports healthy and running. An earlier read reports down and degraded. Report
that state as normal rather than as a failure.
Print a mutating command. Run none.
The operator runs every command that changes the host. You print the command, the precondition, and the risk.
These commands and edits change the host:
hydrascale apply,hydrascale add <id>, andhydrascale remove <id>.hydrascale installandhydrascale serve.sudo systemctl start hydrascale,sudo systemctl stop hydrascale, andsudo systemctl reload hydrascale.- An edit of
/etc/hydrascale/config.yamlor of/etc/hydrascale/secrets.yaml.
hydrascale apply --dry-run prints the actions of a reconciliation, but apply is a
mutating command. Run hydrascale diff instead. It prints the same difference.
When the operator asks for a command that stops a tailnet, print the command and the risk. The operator decides.
The mode enforce and the access block
Warning — a configuration file that holds no access block loses every path between two
tailnets under the mode enforce. State this risk before you print a command that
starts version 1.0.
The daemon writes a preserving rule set on the first start of version 1.0, and it records
the event access.migrated. That rule set carries each tailnet to the internet. It
carries no traffic from one tailnet to another tailnet.
The operator sets the mode observe first. The mode observe writes a kernel log line
for a packet that no rule allows, and it then accepts that packet. The mode enforce
denies that packet. Print this order:
- Start the service with
sudo systemctl start hydrascale. - Confirm the event
access.migratedin the journal. - Set
access.mode: observein/etc/hydrascale/config.yaml. - Apply the mode with
sudo systemctl reload hydrascale. - Use the host for a day.
- Read the would-deny log lines.
- Add one rule for each path that the log names.
- Set
access.mode: enforceonly after the log names no further path.
The daemon detects the migration by the presence of the access key.
internal/config/migrate.go:72 returns early when the configuration file already holds an
access block. An access block that the operator writes before the first start
therefore suppresses the migration. docs/UPGRADING.md holds both orders and the full
procedure. Read it before you print an upgrade step.
The console
internal/api/console.go:15 states the risk of the console:
The console has no authentication. Any local account on the host can reach the console listener and can drive a root daemon.
The console listener binds a loopback address only, and StartConsole refuses and logs
any other address. internal/config/console.go:10 holds the default address
127.0.0.1:9443.
An SSH forward reaches the console from another machine. Print this command for the
operator. Print the address http://127.0.0.1:9443 for the browser as well:
ssh -L 9443:127.0.0.1:9443 <host>
Signals
- GitHub stars
- 34
- Forks
- 2
- Last commit
- Aug 2026
Advanced
- Catalog kind
- skill
- Gateway key
hydrascale-setup- Source
- github.com/crank-git/hydrascale