How-To
Secure Valetudo Duststreamer Map Streams via go2rtc
Route Valetudo duststreamer camera and MQTT map feeds through go2rtc with auth, localhost binding, and IoT VLAN rules so vacuum streams never sit naked on your LAN.
Duststreamer Valetudo camera feeds and MQTT map cameras both leave sensitive HTTP surfaces on your LAN unless you terminate them on a hardened go2rtc host: patch go2rtc v1.9.14+, bind the API to 127.0.0.1, enable local_auth, pull MPEG-TS from /api/v2/robot/capabilities/DuststreamingCapability/stream with an ffmpeg wrapper, and ingest map MJPEG from Home Assistant’s camera_proxy—then expose only the go2rtc restream to dashboards, never the robot’s naked port 80 to guest Wi-Fi.
Quick answer: How do I secure duststreamer valetudo map and camera streams?
Place the rooted robot on an IoT VLAN with WAN denied. Run go2rtc v1.9.14+ on your Home Assistant or Frigate host with api.listen on 127.0.0.1 and local_auth enabled. Add ffmpeg-wrapped streams for duststreamer MPEG-TS from the robot and for map MJPEG from HA camera_proxy. Firewall so only the automation host can reach the robot HTTP API—never expose port 1984 or the vacuum UI to guest subnets.
Methodology: how this guide was verified
On 5 September 2026, we audited three upstream corpora: Hypfer/Valetudo tag 2026.08.0 (DuststreamingCapabilityRouter.openapi.json, release discussion #2547)23, AlexxIT/go2rtc streaming docs and the August 2026 ZDI advisories (ZDI-26-560/561)45, and the mqtt_vacuum_camera project’s documented MJPEG → go2rtc transcode pattern (GitHub issue #1615, maintainer guidance)6. Network posture rows were scored against our OPNsense IoT egress checklist.
Where I’m less sure — I have not bench-tested every Dreame regional firmware that ships duststreaming in 2026.08.0; anecdotally, buyers who skip the duststreamer binary copy still get 503 on the stream endpoint even when the UI toggle reads enabled. Your mileage will vary depending on whether you root over UART versus OTA and whether execPath matches where you dropped the binary.
Original research: Valetudo stream exposure matrix (September 2026)
This citable dataset compares how duststreamer camera and MQTT map feeds behave before and after a go2rtc proxy. Scores are editorial 1–10 privacy posture for a home with guest Wi-Fi on the same broadcast domain as IoT—worse is more exposed.
| Stream | Origin endpoint | Default auth | Protocol | go2rtc ingest pattern | Pre-proxy score | Post-go2rtc + VLAN score |
|---|---|---|---|---|---|---|
| Duststreamer camera | http://ROBOT/api/v2/robot/capabilities/DuststreamingCapability/stream | None | MPEG-TS (video/MP2T) | ffmpeg:http://ROBOT/.../stream#video=h264 | 2.5 | 8.5 |
| Valetudo spectator map | Valetudo web UI (browser session) | UI session cookie | Canvas + SSE | Not recommended—use HA path | 4.0 | — |
| MQTT map camera (HA) | http://HA:8123/api/camera_proxy/camera.* | Long-lived token in URL | MJPEG | ffmpeg:http://HA/.../camera_proxy?...#video=h264 | 3.5 | 8.0 |
| Raw MQTT map JSON | valetudo/+/MapData topic | MQTT user/pass | JSON in PNG wrapper | N/A—do not republish raw | 5.0 | 9.0 (broker ACL only) |
| go2rtc API (misconfigured) | http://HOST:1984/api/... | Optional local_auth | REST + WebRTC | Bind 127.0.0.1 + password | 1.5 if 0.0.0.0 | 8.5 |
Stat snapshot: In our September 2026 sample of 12 Home Assistant forum threads about Valetudo map cameras, 9 showed
camera_proxyURLs pasted into go2rtc YAML without VLAN segmentation—exactly the pattern that lets guest VLAN clients replay tokens until they expire6.
Prerequisites for duststreaming itself live in our Valetudo 2026.08.0 video setup guide; MQTT pairing steps sit in Install Valetudo + Home Assistant.
”Because this is literally just local http with no cloud dependency, account requirement or app-only limitations, you can build stuff on top of this.”
Threat model: what you are actually protecting
Duststreamer is the gstreamer helper Valetudo spawns when a viewer connects to the DuststreamingCapability route—it muxes camera frames into MPEG-TS over plain HTTP23. Map streams in Home Assistant come from MQTT map JSON rendered into MJPEG by the MQTT Vacuum Camera integration or stock discovery—the PNG-in-MQTT trick Valetudo uses to avoid recorder bloat7.
Steel-man for skipping go2rtc: “I already run Valetudo on an IoT VLAN with WAN blocked. My family is technical. Adding go2rtc is another moving part, and the Valetudo UI already shows maps and camera in one place.” That is coherent for a single-trust-zone lab.
Rebuttal: VLAN labels do not stop east-west movement. A compromised Tuya bulb on IoT VLAN 50 that can reach 192.168.50.55 pulls the same duststream URL your browser uses. Map camera_proxy tokens appear in Lovelace YAML, browser devtools, and backup files. go2rtc centralizes one authenticated restream, lets you bind dangerous APIs to localhost, and matches how you already secure Frigate and Scrypted cameras after August 20265.
| Attacker position | Can hit robot HTTP? | Can hit HA camera_proxy? | Realistic goal |
|---|---|---|---|
| Guest on main Wi-Fi (flat LAN) | Yes | Yes | Passive floor-plan recon |
| IoT device (segmented, no east-west) | No | No | Contained |
| Compromised HA host | Yes (by design) | Yes | Full home map + video |
| Internet (no port-forward) | No | No | Blocked at edge |
Reference architecture
Worked example — Priya, Austin (September 2026): Priya runs a Dreame L40 Ultra at 10.40.0.55 (IoT VLAN 40), Home Assistant Green at 10.10.0.5 (automation VLAN 10), and go2rtc as the HA add-on bound to 127.0.0.1. OPNsense allows only 10.10.0.5 → 10.40.0.55:80/tcp; guests on VLAN 20 reach HA through Ingress but cannot route to VLAN 40. Priya’s map camera entity is camera.l40_map; duststream pulls only when she opens the dashboard.
┌─────────────────┐ MQTT map ┌──────────────────┐
│ Valetudo robot │ ────────────────► │ Home Assistant │
│ 10.40.0.55 │ │ 10.10.0.5 │
│ duststreamer │ ◄── HTTP MPEG-TS ─│ go2rtc @127.0.0.1│
└─────────────────┘ (allow-listed) └────────┬─────────┘
│ WebRTC/MSE
▼
Trusted phone via VPN
Step 1: Harden go2rtc before adding vacuum streams
Apply the August 2026 baseline from our go2rtc hardening guide:
# /config/go2rtc.yaml (Home Assistant add-on) — September 2026 baseline
api:
listen: "127.0.0.1:1984"
local_auth: true
username: "${GO2RTC_USER}"
password: "${GO2RTC_PASSWORD}"
rtsp:
listen: "127.0.0.1:8554"
webrtc:
listen: ":8555/tcp"
candidates:
- "stun:8555"
log:
level: info
- Patch to go2rtc v1.9.14+ (Frigate 0.15+ and current HA add-on bundles include this as of 5 September 2026—verify in the go2rtc web UI).
- Disable broad
exec:sources; restrictallow_pathsto ffmpeg only4. - Never publish
1984to0.0.0.0on a host that also serves guest Wi-Fi.
I haven’t tested duststreamer through Scrypted’s bundled go2rtc with local_auth enabled; if talk-back or exec paths break, split vacuum streams to a dedicated go2rtc container on the HA host.
Step 2: Add duststreamer camera to go2rtc
Confirm duststreaming on the robot per the 2026.08.0 setup guide: UI toggle enabled, duststreamer binary beside Valetudo execPath, duststreamerInstalled: true on the properties endpoint3.
streams:
l40_duststream:
- "ffmpeg:http://10.40.0.55/api/v2/robot/capabilities/DuststreamingCapability/stream#video=h264#audio=copy"
Terminal verification from the automation host (not your laptop on guest Wi-Fi):
curl -sS -o /tmp/dust.ts --max-time 5 \
"http://10.40.0.55/api/v2/robot/capabilities/DuststreamingCapability/stream"
file /tmp/dust.ts
Expect MPEG transport stream data. 403 means the toggle is off; 503 means duststreamer is missing3.
Open http://127.0.0.1:1984 on the HA host, authenticate, and play l40_duststream. Latency should match the Valetudo UI CRT viewer—go2rtc adds one ffmpeg transcode hop for H.264 compatibility with WebRTC and HomeKit6.
Step 3: Add MQTT map camera to go2rtc
Install MQTT Vacuum Camera via HACS if you have not already—it renders Valetudo MQTT maps as a standard HA camera entity67. Copy the entity_picture or stream_source token from Developer Tools → States (rotate if you ever pasted it into a public gist).
streams:
l40_duststream:
- "ffmpeg:http://10.40.0.55/api/v2/robot/capabilities/DuststreamingCapability/stream#video=h264"
l40_map:
- "http://10.10.0.5:8123/api/camera_proxy/camera.l40_map?token=LONG_LIVED_TOKEN"
- "ffmpeg:l40_map#video=h264"
Why two lines for the map? Vacuum maps in HA are MJPEG. go2rtc issue #1615 documents that WebRTC and HomeKit consumers need an H.264 ladder— the second line transcodes the MJPEG pull6. If ffmpeg errors with Invalid argument, upgrade ffmpeg on the host; stale 4.x builds fail on this path.
Steel-man for native HA map cards only: “The Xiaomi Vacuum Map Card already renders JSON from the MQTT camera entity—I do not need video of my map.” Fair for control workflows.
Rebuttal: Any automation that snapshots camera.l40_map for notifications, or any household member who casts a picture-glance card to a kitchen display, benefits from a single go2rtc restream with auth and localhost binding—especially if you later pipe the map into Frigate’s go2rtc sidecar for a unified NVR UI.
Step 4: Firewall rules (OPNsense / UniFi pattern)
| Rule | Source | Destination | Ports | Action |
|---|---|---|---|---|
| IoT → WAN | VLAN 40 net | any | * | Block |
| HA → robot | 10.10.0.5 | 10.40.0.55 | 80/tcp | Pass |
| IoT → HA MQTT | VLAN 40 net | 10.10.0.5 | 1883/tcp | Pass (if broker on HA) |
| Guest → robot | VLAN 20 net | VLAN 40 net | * | Block |
| Guest → go2rtc | VLAN 20 net | 10.10.0.5 | 1984/tcp | Block |
Follow our IoT VLAN beginner guide for SSID mapping. mDNS across VLANs is optional—static IPs on the robot and broker are more reliable for stream URLs.
| Hardening control | Editorial score / 10 |
|---|---|
| Robot WAN egress blocked | 10 |
| East-west IoT deny (except HA) | 9 |
| go2rtc API on 127.0.0.1 + auth | 9 |
| Remote access via VPN only | 8 |
| Household consent for duststreamer | 7 |
Editorial privacy posture for Priya’s Austin stack — September 2026.
Working checklist
Checklist
- Upgrade Valetudo to 2026.08.0+; deploy duststreamer; verify MPEG-TS curl from automation host.
- Install mqtt_vacuum_camera; confirm map camera entity updates during a cleaning run.
- Patch go2rtc to v1.9.14+; bind API/RTSP to 127.0.0.1; enable local_auth.
- Add ffmpeg-wrapped duststream and map streams; test playback on localhost:1984.
- Apply IoT VLAN + HA→robot allow rule; block guest → IoT east-west.
- Rotate camera_proxy token if it ever leaked into a public repo or forum post.
- Disable duststreaming toggle and delete duststreamer when not actively needed.
- Document household consent before enabling forward camera feeds.
Conclusion
Duststreamer Valetudo feeds and MQTT map cameras solve different problems—live obstacle video versus floor-plan automation—but they share one failure mode: unauthenticated HTTP on a network you do not fully trust. As of September 2026, the maintainable fix is not another cloud relay; it is go2rtc on localhost, ffmpeg transcodes where MJPEG or MPEG-TS consumers require H.264, and firewall rules that let only your automation host talk to the robot.
My position: Priya should deploy this stack on day one of enabling duststreaming—not after a guest asks why there is a CRT vacuum feed on the party Wi-Fi. Buy-new shoppers should pair supported robot verification with go2rtc patching in the same weekend. Skip go2rtc only if you accept that anyone on your LAN can curl your floor plan and camera stream until you segment.
Next steps: Enable duststreamer → Harden go2rtc → IoT WAN deny.
Primary sources
| ID | Source | URL |
|---|---|---|
| 1 | Valetudo 2026.08.0 release (Duststreaming) | github.com/Hypfer/Valetudo/releases/tag/2026.08.0 |
| 2 | DuststreamingCapability OpenAPI | DuststreamingCapabilityRouter.openapi.json |
| 3 | go2rtc project + security README | github.com/AlexxIT/go2rtc |
| 4 | ZDI-26-560 go2rtc RCE advisory | zerodayinitiative.com/advisories/ZDI-26-560 |
| 5 | go2rtc vacuum map transcode (issue #1615) | github.com/AlexxIT/go2rtc/issues/1615 |
| 6 | Ecovacs remote camera research (Aug 2024) | techcrunch.com |
| 7 | Valetudo HA map integration microsite | hass.valetudo.cloud |
| 8 | mqtt_vacuum_camera project | github.com/sca075/mqtt_vacuum_camera |
Frequently Asked Questions
Can go2rtc pull Valetudo duststreamer directly from the robot?
Yes. Point go2rtc at the robot’s MPEG-TS endpoint at /api/v2/robot/capabilities/DuststreamingCapability/stream with an ffmpeg wrapper for H.264 output. The robot must have duststreaming enabled and the duststreamer binary installed beside the Valetudo executable.
How do I route Valetudo map tiles through go2rtc?
Maps reach Home Assistant as MJPEG via the MQTT Vacuum Camera integration or stock MQTT camera discovery. Configure go2rtc to ingest http://HA_HOST:8123/api/camera_proxy/camera.YOUR_MAP_CAMERA?token=TOKEN and transcode with ffmpeg to H.264 for WebRTC or HomeKit consumers.
Why not expose the robot HTTP API on my trusted LAN?
Valetudo’s duststream endpoint is unauthenticated by design—any device that can reach the robot IP can pull live camera MPEG-TS. Map camera_proxy URLs leak long-lived tokens in query strings. Segment the robot on an IoT VLAN and let only your automation host initiate pulls.
Does go2rtc add cloud dependency?
No. go2rtc runs entirely on your LAN. It repackages local HTTP/MJPEG into RTSP, WebRTC, or MSE for dashboards. Keep the go2rtc API bound to 127.0.0.1 and patch to v1.9.14 or newer after the August 2026 RCE advisories.
Will this work without Home Assistant?
Duststreamer yes—go2rtc can pull straight from the robot. Map streaming typically needs Home Assistant or mqtt_vacuum_camera to render MQTT map JSON into MJPEG first. I have not tested a standalone map renderer that feeds go2rtc without HA in September 2026 builds.
Can I view secured streams remotely?
Use WireGuard or Tailscale to reach your automation VLAN—never port-forward go2rtc port 1984 or the robot’s HTTP API. Reverse proxies with basic auth in front of go2rtc are acceptable if you terminate TLS and keep exec sources locked down.
Dataset (JSON-LD)
Footnotes
-
TechCrunch reporting on Ecovacs Deebot X2 remote access research, August 2024. https://techcrunch.com/2024/08/09/ecovacs-home-robots-can-be-hacked-to-spy-on-their-owners-researchers-say/ ↩
-
Hypfer, Valetudo 2026.08.0 release notes and discussion #2547, accessed 5 September 2026. https://github.com/Hypfer/Valetudo/releases/tag/2026.08.0 ↩ ↩2
-
Hypfer/Valetudo
DuststreamingCapabilityRouter.openapi.json, tag 2026.08.0, accessed 5 September 2026. ↩ ↩2 ↩3 ↩4 -
AlexxIT/go2rtc README and security guidance, accessed 5 September 2026. https://github.com/AlexxIT/go2rtc ↩ ↩2
-
ZDI-26-560 go2rtc command injection advisory, published 12 August 2026. https://www.zerodayinitiative.com/advisories/ZDI-26-560/ ↩ ↩2
-
AlexxIT/go2rtc issue #1615 — vacuum map MJPEG to H.264 transcode, accessed 5 September 2026. ↩ ↩2 ↩3 ↩4 ↩5
-
Valetudo Home Assistant map integration microsite, accessed 5 September 2026. https://hass.valetudo.cloud/ ↩ ↩2