Skip to main content
Use this page to get firewall changes approved for a Cyberwave deployment. Every connection is opened outbound by the edge, the browser, or your application. In a SaaS deployment the customer network generally needs no inbound rules. Values on this page come from the SDK and CLI source and the existing reference pages. Anything not yet documented is called out.

Summary allowlist (SaaS)

This is the minimum egress for an edge node that streams video and runs edge workflows. Add the operator and developer rows from the tables below as needed.

Edge node

Runtime

Why TLS on 443 for the relay

The SDK uses exactly one TURN server. It picks TLS on port 443 on purpose, because that port gets through corporate and industrial firewalls that block 3478 and outbound high UDP ports. The trade-off is that relayed media runs over TCP, which adds latency under packet loss. If the site allows UDP, set CYBERWAVE_WEBRTC_TURN_URL=turn:turn.cyberwave.com:3478 on the edge and open the UDP relay range instead.

Model weights

Edge Core fetches weights only for models that edge workflows load. It tries these sources in order and caches the result in ~/.cyberwave/models/:
  1. A Cyberwave-hosted signed URL.
  2. The upstream URL on the catalog entry. Cyberwave’s ONNX exports are on static.cyberwave.com. Community checkpoints can point to other hosts.
  3. A runtime-managed download. For Ultralytics .pt models this means GitHub releases.
To avoid all three, pre-stage the weight files. Edge Core then never contacts the catalog for those models. See Model cache.

Installation and upgrades

On the site network

Operator browser

Your applications and developer machines

Cloud nodes

A cloud node connects outbound to the MQTT broker and needs no inbound ports. The cloud node page lists 1883 as the default MQTT port. The SDK default is 8883 with TLS. Check which port your cloud node version uses (CYBERWAVE_MQTT_PORT) before you request firewall changes, and prefer TLS.

Self-hosted server

The self-hosted package exposes these services on the server: web frontend, REST API, MQTT for edges, MQTT over WebSocket for browsers, the media service, and a UDP range for WebRTC media (50000–50100). The reference configuration serves them without TLS. Put a TLS-terminating proxy in front and agree the final port plan with Cyberwave. Keep the task monitor (Celery Flower) off any customer-facing network. Even when self-hosted, the media service’s ICE configuration points at Cyberwave’s hosted STUN/TURN (turn.cyberwave.com) and a public Google STUN server. A self-hosted server therefore still needs egress for video unless you replace them. It also pulls images from Docker Hub, and syncing the catalog from production needs internet access.

Port ranges you may see elsewhere

Two different UDP ranges appear in Cyberwave material. They belong to different components: TCP 5349 (TURN over TLS) appears only in the self-hosted material. The SaaS SDK default is TURN over TLS on 443 at tls.turn.cyberwave.com.

Proxies and TLS inspection

  • HTTP(S) proxy. Proxy support for Edge Core, drivers and the MQTT connection is not documented. MQTT on 8883 is a direct TLS connection and does not go through an HTTP proxy. Plan for direct egress from the edge VLAN.
  • TLS inspection. The SDK verifies the broker certificate (CERT_REQUIRED). If the network re-signs TLS, set CYBERWAVE_MQTT_TLS_CA_CERT to your CA bundle for SDK clients. Otherwise, exempt mqtt.cyberwave.com from inspection.

Bandwidth

Per-stream bandwidth is not documented in general. One driver gives a data point: the Go2 navigation driver exposes CYBERWAVE_H264_BITRATE_KBPS, which defaults to 2500 kbps per H.264 stream. Video goes up only while someone is viewing, recording, or running a cloud consumer. Edge workflows on camera_frame process frames locally.

Next steps

Cyberwave for integrators

Architecture, data flows and deployment options.

Fleet provisioning

Headless installs, naming, monitoring and updates.

Integration surfaces

Which endpoint to use for each business system.

Architecture

How WebRTC, MQTT and Zenoh fit together.