System Architecture¶
High-Level Diagram¶
graph TB
subgraph Internet
USER[Admin Laptop]
WEB[Public Web]
end
subgraph VPS["Strato VPS Host — 217.154.228.231"]
WG["WireGuard VPN<br/>:51820-51822"]
UFW["UFW Firewall"]
subgraph Docker["Docker Containers"]
TRF["Traefik<br/>:80/:443"]
PH["Pi-hole<br/>172.20.10.53"]
CC["Control Center<br/>:8089"]
F2B["Fail2ban Dashboard"]
DOCS["MkDocs<br/>172.20.10.20"]
end
subgraph VM["KVM Virtual Machine — 192.168.10.10"]
AI["AI Sandbox<br/>(openclaw user)"]
VMDOCKER["Docker Engine"]
end
IPT["iptables VM_EGRESS<br/>Chain"]
end
USER -->|"WireGuard"| WG
USER -->|"HTTPS"| TRF
WG --> UFW
TRF --> CC
TRF --> PH
TRF --> F2B
TRF --> DOCS
TRF -->|"VM services"| VM
VM -->|"egress"| IPT
IPT -->|"filtered"| WEB
VM -.->|"DNS"| PH
Component Roles¶
Strato VPS Host¶
The host machine runs Debian 13 and is the foundation of the entire infrastructure. It manages:
- KVM/libvirt — Runs the AI sandbox virtual machine
- Docker CE — Hosts all supporting services
- WireGuard — Three VPN tunnels for secure access
- UFW — Host firewall limiting exposed ports
- iptables — VM_EGRESS chain for AI traffic control
KVM Virtual Machine¶
The AI workspace runs inside a fully isolated KVM virtual machine with:
| Resource | Value |
|---|---|
| IP Address | 192.168.10.10 |
| CPUs | 4 |
| RAM | 16 GB |
| Disk | 200 GB |
| OS | Debian 13 |
| Bridge | virbr0 (192.168.10.1) |
| Users | admin (management), openclaw (AI) |
| Boot | UEFI (OVMF) |
Docker Services¶
All supporting services run as Docker containers on the host:
| Container | Image/Build | Network | Purpose |
|---|---|---|---|
traefik |
traefik:v3 | openclaw-infra (172.20.10.10) | Reverse proxy, TLS termination |
pihole |
pihole/pihole | openclaw-infra (172.20.10.53) | DNS server, ad-blocking |
openclaw-control-center |
Custom (FastAPI) | host network | Firewall management UI |
fail2ban-dashboard |
Custom | openclaw-infra (172.20.10.2) | Ban monitoring UI |
openclaw-docs |
Custom (MkDocs) | openclaw-infra (172.20.10.20) | Infrastructure documentation |
Data Flow¶
Web Request Flow¶
Client → :443 → Traefik → Route matching → Backend service
├── firewall.clsxx.de → Control Center (:8089)
├── pihole.clsxx.de → Pi-hole (:80)
├── traefik.clsxx.de → Traefik dashboard (:8080)
├── fail2ban.clsxx.de → Fail2ban dashboard
├── docs.clsxx.de → MkDocs documentation
└── *.clsxx.de → VM services (dynamic)
All routes use the secure-admin middleware chain: VPN IP whitelist → rate-limit → BasicAuth → security headers.
Exception: /api/* paths on dashboard.clsxx.de and tickets.clsxx.de use secure-api (no BasicAuth) for AI agent access.
External IPs receive HTTP 403 before reaching auth.
AI Egress Flow¶
AI VM (192.168.10.10) → virbr0 bridge → iptables FORWARD chain
→ VM_EGRESS chain
├── ESTABLISHED/RELATED → ACCEPT
├── ICMP → ACCEPT
├── User rules → ACCEPT
├── LOG (VM_BLOCKED)
└── DROP