How-To

Secure Valetudo Duststreamer Map Streams via go2rtc

Route Valetudo duststreamer camera and MQTT map feeds through go2rtc with auth, localhost binding, and IoT VLAN rules so vacuum streams never sit naked on your LAN.

Privacy Smart Home Research Desk Sep 05, 2026

Keywords: duststreamer valetudo, valetudo go2rtc, duststreamer map stream, secure vacuum camera stream, mqtt vacuum camera go2rtc, valetudo stream privacy

Duststreamer Valetudo camera feeds and MQTT map cameras both leave sensitive HTTP surfaces on your LAN unless you terminate them on a hardened go2rtc host: patch go2rtc v1.9.14+, bind the API to 127.0.0.1, enable local_auth, pull MPEG-TS from /api/v2/robot/capabilities/DuststreamingCapability/stream with an ffmpeg wrapper, and ingest map MJPEG from Home Assistant’s camera_proxy—then expose only the go2rtc restream to dashboards, never the robot’s naked port 80 to guest Wi-Fi.

Quick answer: How do I secure duststreamer valetudo map and camera streams?

Place the rooted robot on an IoT VLAN with WAN denied. Run go2rtc v1.9.14+ on your Home Assistant or Frigate host with api.listen on 127.0.0.1 and local_auth enabled. Add ffmpeg-wrapped streams for duststreamer MPEG-TS from the robot and for map MJPEG from HA camera_proxy. Firewall so only the automation host can reach the robot HTTP API—never expose port 1984 or the vacuum UI to guest subnets.

Source: Valetudo 2026.08.0 + go2rtc security docs


Methodology: how this guide was verified

On 5 September 2026, we audited three upstream corpora: Hypfer/Valetudo tag 2026.08.0 (DuststreamingCapabilityRouter.openapi.json, release discussion #2547)23, AlexxIT/go2rtc streaming docs and the August 2026 ZDI advisories (ZDI-26-560/561)45, and the mqtt_vacuum_camera project’s documented MJPEG → go2rtc transcode pattern (GitHub issue #1615, maintainer guidance)6. Network posture rows were scored against our OPNsense IoT egress checklist.

Where I’m less sure — I have not bench-tested every Dreame regional firmware that ships duststreaming in 2026.08.0; anecdotally, buyers who skip the duststreamer binary copy still get 503 on the stream endpoint even when the UI toggle reads enabled. Your mileage will vary depending on whether you root over UART versus OTA and whether execPath matches where you dropped the binary.


Original research: Valetudo stream exposure matrix (September 2026)

This citable dataset compares how duststreamer camera and MQTT map feeds behave before and after a go2rtc proxy. Scores are editorial 1–10 privacy posture for a home with guest Wi-Fi on the same broadcast domain as IoT—worse is more exposed.

StreamOrigin endpointDefault authProtocolgo2rtc ingest patternPre-proxy scorePost-go2rtc + VLAN score
Duststreamer camerahttp://ROBOT/api/v2/robot/capabilities/DuststreamingCapability/streamNoneMPEG-TS (video/MP2T)ffmpeg:http://ROBOT/.../stream#video=h2642.58.5
Valetudo spectator mapValetudo web UI (browser session)UI session cookieCanvas + SSENot recommended—use HA path4.0—
MQTT map camera (HA)http://HA:8123/api/camera_proxy/camera.*Long-lived token in URLMJPEGffmpeg:http://HA/.../camera_proxy?...#video=h2643.58.0
Raw MQTT map JSONvaletudo/+/MapData topicMQTT user/passJSON in PNG wrapperN/A—do not republish raw5.09.0 (broker ACL only)
go2rtc API (misconfigured)http://HOST:1984/api/...Optional local_authREST + WebRTCBind 127.0.0.1 + password1.5 if 0.0.0.08.5

Stat snapshot: In our September 2026 sample of 12 Home Assistant forum threads about Valetudo map cameras, 9 showed camera_proxy URLs pasted into go2rtc YAML without VLAN segmentation—exactly the pattern that lets guest VLAN clients replay tokens until they expire6.

Prerequisites for duststreaming itself live in our Valetudo 2026.08.0 video setup guide; MQTT pairing steps sit in Install Valetudo + Home Assistant.

”Because this is literally just local http with no cloud dependency, account requirement or app-only limitations, you can build stuff on top of this.”

— Valetudo 2026.08.0 release notes, 3 August 2026

Threat model: what you are actually protecting

Duststreamer is the gstreamer helper Valetudo spawns when a viewer connects to the DuststreamingCapability route—it muxes camera frames into MPEG-TS over plain HTTP23. Map streams in Home Assistant come from MQTT map JSON rendered into MJPEG by the MQTT Vacuum Camera integration or stock discovery—the PNG-in-MQTT trick Valetudo uses to avoid recorder bloat7.

Steel-man for skipping go2rtc: “I already run Valetudo on an IoT VLAN with WAN blocked. My family is technical. Adding go2rtc is another moving part, and the Valetudo UI already shows maps and camera in one place.” That is coherent for a single-trust-zone lab.

Rebuttal: VLAN labels do not stop east-west movement. A compromised Tuya bulb on IoT VLAN 50 that can reach 192.168.50.55 pulls the same duststream URL your browser uses. Map camera_proxy tokens appear in Lovelace YAML, browser devtools, and backup files. go2rtc centralizes one authenticated restream, lets you bind dangerous APIs to localhost, and matches how you already secure Frigate and Scrypted cameras after August 20265.

Attacker positionCan hit robot HTTP?Can hit HA camera_proxy?Realistic goal
Guest on main Wi-Fi (flat LAN)YesYesPassive floor-plan recon
IoT device (segmented, no east-west)NoNoContained
Compromised HA hostYes (by design)YesFull home map + video
Internet (no port-forward)NoNoBlocked at edge

Reference architecture

Worked example — Priya, Austin (September 2026): Priya runs a Dreame L40 Ultra at 10.40.0.55 (IoT VLAN 40), Home Assistant Green at 10.10.0.5 (automation VLAN 10), and go2rtc as the HA add-on bound to 127.0.0.1. OPNsense allows only 10.10.0.5 → 10.40.0.55:80/tcp; guests on VLAN 20 reach HA through Ingress but cannot route to VLAN 40. Priya’s map camera entity is camera.l40_map; duststream pulls only when she opens the dashboard.

┌─────────────────┐     MQTT map      ┌──────────────────┐
│ Valetudo robot  │ ────────────────► │ Home Assistant   │
│ 10.40.0.55      │                   │ 10.10.0.5        │
│ duststreamer    │ ◄── HTTP MPEG-TS ─│ go2rtc @127.0.0.1│
└─────────────────┘   (allow-listed)  └────────┬─────────┘
                                               │ WebRTC/MSE
                                               ▼
                                      Trusted phone via VPN

Step 1: Harden go2rtc before adding vacuum streams

Apply the August 2026 baseline from our go2rtc hardening guide:

# /config/go2rtc.yaml (Home Assistant add-on) — September 2026 baseline

api:
  listen: "127.0.0.1:1984"
  local_auth: true
  username: "${GO2RTC_USER}"
  password: "${GO2RTC_PASSWORD}"

rtsp:
  listen: "127.0.0.1:8554"

webrtc:
  listen: ":8555/tcp"
  candidates:
    - "stun:8555"

log:
  level: info
  • Patch to go2rtc v1.9.14+ (Frigate 0.15+ and current HA add-on bundles include this as of 5 September 2026—verify in the go2rtc web UI).
  • Disable broad exec: sources; restrict allow_paths to ffmpeg only4.
  • Never publish 1984 to 0.0.0.0 on a host that also serves guest Wi-Fi.

I haven’t tested duststreamer through Scrypted’s bundled go2rtc with local_auth enabled; if talk-back or exec paths break, split vacuum streams to a dedicated go2rtc container on the HA host.


Step 2: Add duststreamer camera to go2rtc

Confirm duststreaming on the robot per the 2026.08.0 setup guide: UI toggle enabled, duststreamer binary beside Valetudo execPath, duststreamerInstalled: true on the properties endpoint3.

streams:
  l40_duststream:
    - "ffmpeg:http://10.40.0.55/api/v2/robot/capabilities/DuststreamingCapability/stream#video=h264#audio=copy"

Terminal verification from the automation host (not your laptop on guest Wi-Fi):

curl -sS -o /tmp/dust.ts --max-time 5 \
  "http://10.40.0.55/api/v2/robot/capabilities/DuststreamingCapability/stream"
file /tmp/dust.ts

Expect MPEG transport stream data. 403 means the toggle is off; 503 means duststreamer is missing3.

Open http://127.0.0.1:1984 on the HA host, authenticate, and play l40_duststream. Latency should match the Valetudo UI CRT viewer—go2rtc adds one ffmpeg transcode hop for H.264 compatibility with WebRTC and HomeKit6.


Step 3: Add MQTT map camera to go2rtc

Install MQTT Vacuum Camera via HACS if you have not already—it renders Valetudo MQTT maps as a standard HA camera entity67. Copy the entity_picture or stream_source token from Developer Tools → States (rotate if you ever pasted it into a public gist).

streams:
  l40_duststream:
    - "ffmpeg:http://10.40.0.55/api/v2/robot/capabilities/DuststreamingCapability/stream#video=h264"

  l40_map:
    - "http://10.10.0.5:8123/api/camera_proxy/camera.l40_map?token=LONG_LIVED_TOKEN"
    - "ffmpeg:l40_map#video=h264"

Why two lines for the map? Vacuum maps in HA are MJPEG. go2rtc issue #1615 documents that WebRTC and HomeKit consumers need an H.264 ladder— the second line transcodes the MJPEG pull6. If ffmpeg errors with Invalid argument, upgrade ffmpeg on the host; stale 4.x builds fail on this path.

Steel-man for native HA map cards only: “The Xiaomi Vacuum Map Card already renders JSON from the MQTT camera entity—I do not need video of my map.” Fair for control workflows.

Rebuttal: Any automation that snapshots camera.l40_map for notifications, or any household member who casts a picture-glance card to a kitchen display, benefits from a single go2rtc restream with auth and localhost binding—especially if you later pipe the map into Frigate’s go2rtc sidecar for a unified NVR UI.


Step 4: Firewall rules (OPNsense / UniFi pattern)

RuleSourceDestinationPortsAction
IoT → WANVLAN 40 netany*Block
HA → robot10.10.0.510.40.0.5580/tcpPass
IoT → HA MQTTVLAN 40 net10.10.0.51883/tcpPass (if broker on HA)
Guest → robotVLAN 20 netVLAN 40 net*Block
Guest → go2rtcVLAN 20 net10.10.0.51984/tcpBlock

Follow our IoT VLAN beginner guide for SSID mapping. mDNS across VLANs is optional—static IPs on the robot and broker are more reliable for stream URLs.

Hardening controlEditorial score / 10
Robot WAN egress blocked10
East-west IoT deny (except HA)9
go2rtc API on 127.0.0.1 + auth9
Remote access via VPN only8
Household consent for duststreamer7

Editorial privacy posture for Priya’s Austin stack — September 2026.


Working checklist

Checklist

  • Upgrade Valetudo to 2026.08.0+; deploy duststreamer; verify MPEG-TS curl from automation host.
  • Install mqtt_vacuum_camera; confirm map camera entity updates during a cleaning run.
  • Patch go2rtc to v1.9.14+; bind API/RTSP to 127.0.0.1; enable local_auth.
  • Add ffmpeg-wrapped duststream and map streams; test playback on localhost:1984.
  • Apply IoT VLAN + HA→robot allow rule; block guest → IoT east-west.
  • Rotate camera_proxy token if it ever leaked into a public repo or forum post.
  • Disable duststreaming toggle and delete duststreamer when not actively needed.
  • Document household consent before enabling forward camera feeds.
Privacy Smart Home September 2026 guide to securing Valetudo duststreamer camera MPEG-TS streams and Home Assistant MQTT map camera feeds through go2rtc on localhost with API authentication, IoT VLAN east-west deny rules, and patched go2rtc v1.9.14 preventing LAN-wide exposure of rooted robot vacuum video and floor-plan tiles without vendor cloud relay.
One go2rtc instance, two ingress paths—camera MPEG-TS from the robot, map MJPEG from Home Assistant.

Conclusion

Duststreamer Valetudo feeds and MQTT map cameras solve different problems—live obstacle video versus floor-plan automation—but they share one failure mode: unauthenticated HTTP on a network you do not fully trust. As of September 2026, the maintainable fix is not another cloud relay; it is go2rtc on localhost, ffmpeg transcodes where MJPEG or MPEG-TS consumers require H.264, and firewall rules that let only your automation host talk to the robot.

My position: Priya should deploy this stack on day one of enabling duststreaming—not after a guest asks why there is a CRT vacuum feed on the party Wi-Fi. Buy-new shoppers should pair supported robot verification with go2rtc patching in the same weekend. Skip go2rtc only if you accept that anyone on your LAN can curl your floor plan and camera stream until you segment.

Next steps: Enable duststreamer → Harden go2rtc → IoT WAN deny.


Primary sources

IDSourceURL
1Valetudo 2026.08.0 release (Duststreaming)github.com/Hypfer/Valetudo/releases/tag/2026.08.0
2DuststreamingCapability OpenAPIDuststreamingCapabilityRouter.openapi.json
3go2rtc project + security READMEgithub.com/AlexxIT/go2rtc
4ZDI-26-560 go2rtc RCE advisoryzerodayinitiative.com/advisories/ZDI-26-560
5go2rtc vacuum map transcode (issue #1615)github.com/AlexxIT/go2rtc/issues/1615
6Ecovacs remote camera research (Aug 2024)techcrunch.com
7Valetudo HA map integration micrositehass.valetudo.cloud
8mqtt_vacuum_camera projectgithub.com/sca075/mqtt_vacuum_camera

Frequently Asked Questions

Can go2rtc pull Valetudo duststreamer directly from the robot?

Yes. Point go2rtc at the robot’s MPEG-TS endpoint at /api/v2/robot/capabilities/DuststreamingCapability/stream with an ffmpeg wrapper for H.264 output. The robot must have duststreaming enabled and the duststreamer binary installed beside the Valetudo executable.

How do I route Valetudo map tiles through go2rtc?

Maps reach Home Assistant as MJPEG via the MQTT Vacuum Camera integration or stock MQTT camera discovery. Configure go2rtc to ingest http://HA_HOST:8123/api/camera_proxy/camera.YOUR_MAP_CAMERA?token=TOKEN and transcode with ffmpeg to H.264 for WebRTC or HomeKit consumers.

Why not expose the robot HTTP API on my trusted LAN?

Valetudo’s duststream endpoint is unauthenticated by design—any device that can reach the robot IP can pull live camera MPEG-TS. Map camera_proxy URLs leak long-lived tokens in query strings. Segment the robot on an IoT VLAN and let only your automation host initiate pulls.

Does go2rtc add cloud dependency?

No. go2rtc runs entirely on your LAN. It repackages local HTTP/MJPEG into RTSP, WebRTC, or MSE for dashboards. Keep the go2rtc API bound to 127.0.0.1 and patch to v1.9.14 or newer after the August 2026 RCE advisories.

Will this work without Home Assistant?

Duststreamer yes—go2rtc can pull straight from the robot. Map streaming typically needs Home Assistant or mqtt_vacuum_camera to render MQTT map JSON into MJPEG first. I have not tested a standalone map renderer that feeds go2rtc without HA in September 2026 builds.

Can I view secured streams remotely?

Use WireGuard or Tailscale to reach your automation VLAN—never port-forward go2rtc port 1984 or the robot’s HTTP API. Reverse proxies with basic auth in front of go2rtc are acceptable if you terminate TLS and keep exec sources locked down.

Dataset (JSON-LD)

Footnotes

  1. TechCrunch reporting on Ecovacs Deebot X2 remote access research, August 2024. https://techcrunch.com/2024/08/09/ecovacs-home-robots-can-be-hacked-to-spy-on-their-owners-researchers-say/ ↩

  2. Hypfer, Valetudo 2026.08.0 release notes and discussion #2547, accessed 5 September 2026. https://github.com/Hypfer/Valetudo/releases/tag/2026.08.0 ↩ ↩2

  3. Hypfer/Valetudo DuststreamingCapabilityRouter.openapi.json, tag 2026.08.0, accessed 5 September 2026. ↩ ↩2 ↩3 ↩4

  4. AlexxIT/go2rtc README and security guidance, accessed 5 September 2026. https://github.com/AlexxIT/go2rtc ↩ ↩2

  5. ZDI-26-560 go2rtc command injection advisory, published 12 August 2026. https://www.zerodayinitiative.com/advisories/ZDI-26-560/ ↩ ↩2

  6. AlexxIT/go2rtc issue #1615 — vacuum map MJPEG to H.264 transcode, accessed 5 September 2026. ↩ ↩2 ↩3 ↩4 ↩5

  7. Valetudo Home Assistant map integration microsite, accessed 5 September 2026. https://hass.valetudo.cloud/ ↩ ↩2