Control Center Overview
The OpenClaw Control Center is a FastAPI web application that serves as the unified management dashboard for the AI sandbox infrastructure. It runs in a Docker container with NET_ADMIN capability on the host network namespace, giving it direct access to iptables for firewall management.
Features
| Feature |
Description |
| Firewall Management |
iptables VM_EGRESS chain with CRUD rules, profiles, killswitch |
| Access Profiles |
One-click preset levels: Locked, Minimal, Development, Unrestricted |
| DNS Monitoring |
Pi-hole v5/v6 integration: stats, queries, top domains, ad-blocking toggle |
| VPN Monitoring |
Real-time WireGuard tunnel status via wg show all dump |
| Fail2ban Management |
Jail status, unban IPs, set ban times, view whitelist |
| Structured Audit |
JSON-lines logging with severity levels for all actions |
| Web Service Routing |
Traefik file provider management for VM service exposure |
| Secrets Manager |
Centralized YAML secrets store with masked UI + SSH deployment to VM |
| Emergency Stop |
Instant killswitch that drops all VM traffic |
Technical Stack
| Component |
Technology |
| Backend |
Python 3.12 + FastAPI + Uvicorn (modular: routers + services) |
| Frontend |
Vanilla HTML/CSS/JS (single-page app) |
| Container |
Docker with privileged: true, pid: host, network_mode: host |
| Firewall |
iptables (direct subprocess calls) |
| Fail2ban |
nsenter into host PID namespace → fail2ban-client |
| VPN Monitor |
WireGuard CLI (wg show all dump) |
| DNS Client |
aiohttp → Pi-hole REST API (v5/v6 compatible) |
| Config Store |
JSON file (/app/data/rules.json) |
| Audit Store |
JSON-lines file (/app/data/audit.jsonl) |
| Route Config |
YAML file (Traefik file provider) |
Access
| Property |
Value |
| URL |
https://firewall.clsxx.de |
| Port |
8089 (internal) |
| Auth |
BasicAuth via Traefik |
| VPN Required |
Yes (strato-host tunnel) |
Design Inspiration
The audit logging system and security pipeline visualization are inspired by NVIDIA NeMo Guardrails:
- NeMo Guardrails operates at the LLM conversation layer (input/output rails, jailbreak detection, PII masking)
- Our Control Center operates at the infrastructure layer (network, containers, firewall)
- We adopted NeMo's architectural concepts: structured audit logging with decision reasoning, severity levels, and pipeline visualization