Skip to content

Control Center Overview

The OpenClaw Control Center is a FastAPI web application that serves as the unified management dashboard for the AI sandbox infrastructure. It runs in a Docker container with NET_ADMIN capability on the host network namespace, giving it direct access to iptables for firewall management.

Features

Feature Description
Firewall Management iptables VM_EGRESS chain with CRUD rules, profiles, killswitch
Access Profiles One-click preset levels: Locked, Minimal, Development, Unrestricted
DNS Monitoring Pi-hole v5/v6 integration: stats, queries, top domains, ad-blocking toggle
VPN Monitoring Real-time WireGuard tunnel status via wg show all dump
Fail2ban Management Jail status, unban IPs, set ban times, view whitelist
Structured Audit JSON-lines logging with severity levels for all actions
Web Service Routing Traefik file provider management for VM service exposure
Secrets Manager Centralized YAML secrets store with masked UI + SSH deployment to VM
Emergency Stop Instant killswitch that drops all VM traffic

Technical Stack

Component Technology
Backend Python 3.12 + FastAPI + Uvicorn (modular: routers + services)
Frontend Vanilla HTML/CSS/JS (single-page app)
Container Docker with privileged: true, pid: host, network_mode: host
Firewall iptables (direct subprocess calls)
Fail2ban nsenter into host PID namespace → fail2ban-client
VPN Monitor WireGuard CLI (wg show all dump)
DNS Client aiohttp → Pi-hole REST API (v5/v6 compatible)
Config Store JSON file (/app/data/rules.json)
Audit Store JSON-lines file (/app/data/audit.jsonl)
Route Config YAML file (Traefik file provider)

Access

Property Value
URL https://firewall.clsxx.de
Port 8089 (internal)
Auth BasicAuth via Traefik
VPN Required Yes (strato-host tunnel)

Design Inspiration

The audit logging system and security pipeline visualization are inspired by NVIDIA NeMo Guardrails:

  • NeMo Guardrails operates at the LLM conversation layer (input/output rails, jailbreak detection, PII masking)
  • Our Control Center operates at the infrastructure layer (network, containers, firewall)
  • We adopted NeMo's architectural concepts: structured audit logging with decision reasoning, severity levels, and pipeline visualization