Security Layers¶
The OpenClaw infrastructure implements defense in depth with seven independent security layers. Each layer provides protection even if other layers are compromised.
Layer 1: WireGuard VPN¶
What it does: Encrypts all admin traffic and restricts access to authenticated clients.
- Three tunnels with different access scopes
- PresharedKeys for post-quantum security
strato-vmandopenclaw-aitunnels can only forward to the VM, not access host services directly- Public SSH is disabled — only VPN SSH is allowed
- WireGuard interfaces are explicitly allowed in
/etc/ufw/before.rules(before conntrack INVALID drop)
# /etc/ufw/before.rules — allows WireGuard VPN traffic
-A ufw-before-input -i strato-host -s 10.0.0.0/24 -j ACCEPT
-A ufw-before-input -i strato-vm -s 10.0.1.0/24 -j ACCEPT
-A ufw-before-input -i openclaw-ai -s 10.0.3.0/24 -j ACCEPT
Layer 2: Host Firewall (UFW)¶
What it does: Restricts which ports are publicly accessible.
Only these ports are open:
| Port | Service |
|---|---|
| 80/tcp | HTTP → HTTPS redirect |
| 443/tcp | HTTPS (Traefik) |
| 51820-51822/udp | WireGuard tunnels |
SSH (port 22) is NOT publicly accessible. It's only reachable via VPN.
Layer 3: VPN IP Whitelist¶
What it does: All admin dashboards are only accessible from VPN/internal subnets.
Traefik secure-admin middleware chain applies to every service:
API Exception
API paths (/api/...) on dashboard.clsxx.de and tickets.clsxx.de use the secure-api chain instead — VPN-only without BasicAuth — so AI agents can call them programmatically via the api-proxy.
vpn-whitelist:
ipAllowList:
sourceRange:
- "127.0.0.1/8"
- "10.0.0.0/24" # strato-host VPN
- "10.0.1.0/24" # strato-vm VPN
- "10.0.3.0/24" # openclaw-ai VPN
- "192.168.10.0/24" # VM bridge
- "172.20.10.0/24" # Docker openclaw-infra
External IPs receive HTTP 403 immediately — they never reach BasicAuth. Direct IP access to the server returns HTTP 503 (default-deny catch-all router).
Layer 4: AI Access Control (VM_EGRESS)¶
What it does: Controls what the AI's virtual machine can access on the internet.
The Control Center manages an iptables chain called VM_EGRESS:
FORWARD chain → VM_EGRESS (for traffic from 192.168.10.10 via virbr0)
├── ESTABLISHED/RELATED → ACCEPT
├── ICMP → ACCEPT
├── User-defined rules → ACCEPT
├── LOG (VM_BLOCKED: prefix)
└── DROP
Four profiles:
| Profile | Rules |
|---|---|
| Locked | DNS to gateway only |
| Minimal | DNS + HTTPS (443) |
| Development | DNS + HTTP + HTTPS + SSH + Git |
| Unrestricted | Chain accepts all |
Layer 5: VM Isolation (KVM)¶
What it does: Hardware-level isolation prevents the AI from accessing the host.
- Full KVM virtualization with UEFI boot
- Separate kernel, filesystem, and process space
- Bridge networking (virbr0) — no host filesystem access
- All VM traffic passes through the host's iptables (FORWARD chain)
Layer 6: Docker Network Isolation¶
What it does: Prevents Docker containers from making unexpected connections.
- Custom
docker-egressnetwork (172.20.10.0/24) with controlled routing - Containers cannot reach the host's management interfaces
- Inter-container communication is restricted to the overlay network
Layer 7: Authentication¶
What it does: Multiple authentication mechanisms prevent unauthorized access.
| Mechanism | Scope |
|---|---|
| SSH key-only | All SSH connections (password auth disabled) |
| BasicAuth | All Traefik-proxied dashboards |
| Fail2ban | Blocks IPs after failed login attempts |
| Pi-hole session auth | Pi-hole API access |
Layer 8: Secrets Management¶
What it does: Centralizes all credentials in a single encrypted store with secure VM delivery.
| Aspect | Implementation |
|---|---|
| Master store | /opt/secrets/secrets.yml on host (root-only) |
| VM delivery | Per-app .env files via SSH (mode 600, root-only) |
| Manifest | Key names only, readable by openclaw user |
| API masking | Values shown as ••••••••xxxx (last 4 chars) |
| Audit trail | All CRUD operations logged |
Secrets never pass through the AI VM in plaintext — only the Control Center on the host has access to the master YAML.
Attack Surface Analysis¶
graph LR
subgraph Public
P80["Port 80"]
P443["Port 443"]
PWG["Ports 51820-51822"]
end
subgraph Protected
SSH["SSH :22"]
CC["Control Center :8089"]
PH["Pi-hole :53"]
TRF["Traefik :8080"]
end
P80 -->|"redirect"| P443
P443 -->|"Traefik + BasicAuth<br/>+ VPN IP whitelist"| CC
P443 -->|"Traefik + BasicAuth<br/>+ VPN IP whitelist"| TRF
PWG -->|"WireGuard auth"| SSH
PWG -->|"WireGuard auth"| CC
Only ports 80, 443, and the WireGuard ports are reachable from the public internet. Everything else requires VPN authentication first.