OpenClaw Documentation¶
Welcome to the comprehensive documentation for the OpenClaw AI Sandbox Infrastructure.
What is OpenClaw?¶
OpenClaw is a secure, self-hosted AI development environment running on a dedicated Strato VPS. It provides:
- An isolated AI sandbox — A KVM virtual machine with controlled internet access
- Fine-grained network control — iptables-based firewall managed via a web UI
- VPN-only admin access — All management is behind WireGuard tunnels
- Full observability — DNS monitoring, VPN status, structured audit logging
- Web service exposure — Traefik reverse proxy with automatic HTTPS
Quick Links¶
| Topic | Description |
|---|---|
| Quick Start | Get up and running in 5 minutes |
| System Architecture | How everything fits together |
| Control Center | The web-based management dashboard |
| VPN Access | WireGuard tunnel configuration |
| API Reference | Complete REST API documentation |
| Emergency Procedures | What to do when things go wrong |
Infrastructure Summary¶
| Component | Details |
|---|---|
| Host | Strato VPS — Debian 13, 217.154.228.231 |
| VM | KVM — Debian 13, 192.168.10.10, 4 CPUs, 16 GB RAM, 200 GB |
| VPN | 3 WireGuard tunnels (admin, VM access, AI) |
| Domain | *.clsxx.de with Let's Encrypt TLS |
| Control Center | FastAPI on port 8089 at https://firewall.clsxx.de |
| DNS | Pi-hole v6 at https://pihole.clsxx.de |
| Routing | Traefik at https://traefik.clsxx.de |
| Security | Fail2ban at https://fail2ban.clsxx.de |
| Services | Trading, Nextcloud, Gitea, Mailserver, Portainer, Part Finder, Dashboard — all VPN-only |
Documentation Service¶
This documentation is served by MkDocs Material and is accessible at https://docs.clsxx.de. It is auto-served from Markdown source files and updates when the container is rebuilt.