Skip to content

Security Layers

The OpenClaw infrastructure implements defense in depth with seven independent security layers. Each layer provides protection even if other layers are compromised.

Layer 1: WireGuard VPN

What it does: Encrypts all admin traffic and restricts access to authenticated clients.

  • Three tunnels with different access scopes
  • PresharedKeys for post-quantum security
  • strato-vm and openclaw-ai tunnels can only forward to the VM, not access host services directly
  • Public SSH is disabled — only VPN SSH is allowed
  • WireGuard interfaces are explicitly allowed in /etc/ufw/before.rules (before conntrack INVALID drop)
# /etc/ufw/before.rules — allows WireGuard VPN traffic
-A ufw-before-input -i strato-host -s 10.0.0.0/24 -j ACCEPT
-A ufw-before-input -i strato-vm -s 10.0.1.0/24 -j ACCEPT
-A ufw-before-input -i openclaw-ai -s 10.0.3.0/24 -j ACCEPT

Layer 2: Host Firewall (UFW)

What it does: Restricts which ports are publicly accessible.

Only these ports are open:

Port Service
80/tcp HTTP → HTTPS redirect
443/tcp HTTPS (Traefik)
51820-51822/udp WireGuard tunnels

SSH (port 22) is NOT publicly accessible. It's only reachable via VPN.

Layer 3: VPN IP Whitelist

What it does: All admin dashboards are only accessible from VPN/internal subnets.

Traefik secure-admin middleware chain applies to every service:

API Exception

API paths (/api/...) on dashboard.clsxx.de and tickets.clsxx.de use the secure-api chain instead — VPN-only without BasicAuth — so AI agents can call them programmatically via the api-proxy.

vpn-whitelist:
  ipAllowList:
    sourceRange:
      - "127.0.0.1/8"
      - "10.0.0.0/24"      # strato-host VPN
      - "10.0.1.0/24"      # strato-vm VPN
      - "10.0.3.0/24"      # openclaw-ai VPN
      - "192.168.10.0/24"  # VM bridge
      - "172.20.10.0/24"   # Docker openclaw-infra

External IPs receive HTTP 403 immediately — they never reach BasicAuth. Direct IP access to the server returns HTTP 503 (default-deny catch-all router).

Layer 4: AI Access Control (VM_EGRESS)

What it does: Controls what the AI's virtual machine can access on the internet.

The Control Center manages an iptables chain called VM_EGRESS:

FORWARD chain → VM_EGRESS (for traffic from 192.168.10.10 via virbr0)
                ├── ESTABLISHED/RELATED → ACCEPT
                ├── ICMP → ACCEPT
                ├── User-defined rules → ACCEPT
                ├── LOG (VM_BLOCKED: prefix)
                └── DROP

Four profiles:

Profile Rules
Locked DNS to gateway only
Minimal DNS + HTTPS (443)
Development DNS + HTTP + HTTPS + SSH + Git
Unrestricted Chain accepts all

Layer 5: VM Isolation (KVM)

What it does: Hardware-level isolation prevents the AI from accessing the host.

  • Full KVM virtualization with UEFI boot
  • Separate kernel, filesystem, and process space
  • Bridge networking (virbr0) — no host filesystem access
  • All VM traffic passes through the host's iptables (FORWARD chain)

Layer 6: Docker Network Isolation

What it does: Prevents Docker containers from making unexpected connections.

  • Custom docker-egress network (172.20.10.0/24) with controlled routing
  • Containers cannot reach the host's management interfaces
  • Inter-container communication is restricted to the overlay network

Layer 7: Authentication

What it does: Multiple authentication mechanisms prevent unauthorized access.

Mechanism Scope
SSH key-only All SSH connections (password auth disabled)
BasicAuth All Traefik-proxied dashboards
Fail2ban Blocks IPs after failed login attempts
Pi-hole session auth Pi-hole API access

Layer 8: Secrets Management

What it does: Centralizes all credentials in a single encrypted store with secure VM delivery.

Aspect Implementation
Master store /opt/secrets/secrets.yml on host (root-only)
VM delivery Per-app .env files via SSH (mode 600, root-only)
Manifest Key names only, readable by openclaw user
API masking Values shown as ••••••••xxxx (last 4 chars)
Audit trail All CRUD operations logged

Secrets never pass through the AI VM in plaintext — only the Control Center on the host has access to the master YAML.

Attack Surface Analysis

graph LR
    subgraph Public
        P80["Port 80"]
        P443["Port 443"]
        PWG["Ports 51820-51822"]
    end

    subgraph Protected
        SSH["SSH :22"]
        CC["Control Center :8089"]
        PH["Pi-hole :53"]
        TRF["Traefik :8080"]
    end

    P80 -->|"redirect"| P443
    P443 -->|"Traefik + BasicAuth<br/>+ VPN IP whitelist"| CC
    P443 -->|"Traefik + BasicAuth<br/>+ VPN IP whitelist"| TRF
    PWG -->|"WireGuard auth"| SSH
    PWG -->|"WireGuard auth"| CC

Only ports 80, 443, and the WireGuard ports are reachable from the public internet. Everything else requires VPN authentication first.