Network SDR sharing¶
AryaOS can serve an onboard SDR raw over the network so a remote operator can
tune and demodulate it from a desktop client (SDR++, SDRangel, GQRX, SDR#,
dump1090, ...) instead of decoding it on the box. A dongle can only do one job at
A time, so sharing a dongle stops its decoder first.
Raw SDR sharing is unauthenticated - opt-in only
Both servers below give any client that can reach the port full control of
The dongle (tuning + raw IQ). They are off by default, and the firewall
does not open their ports on any zone. Enable a share only on a trusted
or VPN network - open the firewall service deliberately, or bind the server
to your VPN address (AOS_RTLTCP_BIND /
AOS_SOAPY_BIND / AOS_SPYSERVER_BIND). Turn it back off when you are done.
Servers¶
| Server | Devices | Client connects as | Port |
|---|---|---|---|
| rtl_tcp | RTL-SDR only (per dongle) | rtl_tcp host:port (SDR#, GQRX, dump1090...) |
1234 + index |
| SoapyRemote | any SoapySDR device (RTL / LimeSDR / Airspy / HackRF) | driver=remote,remote=<host> (SDR++, SDRangel) |
55132 |
| SpyServer | RTL-SDR (per dongle) | spyserver://<host>:<port> (SDR#, SDRangel, SDR++) |
5555 + index |
!!! note "SpyServer is an optional proprietary component" The Airspy spyserver binary is not in
Debian. AryaOS fetches it at build time
from airspy.com. If the builder was offline
The mode is unavailable and aryaos-sdr
share N spyserver reports so (check
share-status > "spyserver_available").
SpyServer streams a compressed, decimated
slice - lighter on the network than
rtl_tcp's raw IQ. It never advertises the
box in the public SpyServer directory
(list_in_directory = 0).
Sharing a dongle¶
aryaos-sdr list # find the dongle index
sudo aryaos-sdr share 0 rtltcp # RTL-SDR 0 over rtl_tcp on :1234
sudo aryaos-sdr share 0 soapy # all SoapySDR devices over SoapyRemote :55132
sudo aryaos-sdr share 0 spyserver # RTL-SDR 0 over SpyServer on :5555
sudo aryaos-sdr share 0 off # stop sharing (then re-apply a role to decode)
aryaos-sdr share-status # JSON: which share servers are running
Resume normal decoding after sharing with sudo aryaos-role set <role>.
Opening access (deliberately)¶
The share ports are closed by default. To reach a share, either bind to the VPN:
# rtl_tcp bound to the Tailscale address only:
sudo systemctl edit aryaos-rtltcp@0 # add: [Service]\nEnvironment=AOS_RTLTCP_BIND=100.x.y.z
...or open the firewall service on a trusted zone (the definitions ship but are attached to no zone):
sudo firewall-cmd --zone=public --add-service=aryaos-rtltcp # or aryaos-soapyremote / aryaos-spyserver
# make permanent only if you really want it always-on:
sudo firewall-cmd --permanent --zone=public --add-service=aryaos-rtltcp
See also¶
- Radios & SDRs - SDR serials and decoder assignment
- SIGINT / wideband (LimeSDR) - the dragonegg laydown
- VPN (Tailscale) - the recommended path for remote SDR access