Skip to content

Overview

What You're Working With

The OpenClaw project is a secure AI development environment hosted on a remote Strato VPS. The core idea is simple:

  1. An AI assistant runs inside an isolated virtual machine (KVM)
  2. You control exactly what internet access the AI has
  3. All admin access is VPN-only — nothing is publicly exposed except web services you explicitly allow
  4. Every security-relevant action is logged and auditable

Key Concepts

The AI Sandbox

The AI runs inside a KVM virtual machine at 192.168.10.10. This provides hardware-level isolation — the AI physically cannot access the host machine's filesystem, processes, or network interfaces.

The Control Center

The Control Center is a FastAPI web application that manages the VM's network access. It provides:

  • Firewall rules via an iptables chain (VM_EGRESS)
  • Access level profiles (Locked → Minimal → Development → Unrestricted)
  • DNS monitoring via Pi-hole integration
  • VPN tunnel status via WireGuard
  • Structured audit logging for every action

VPN-Only Access

All administrative access (SSH, dashboards) requires an active WireGuard VPN connection. There are three tunnels:

Tunnel Subnet Purpose
strato-host 10.0.0.0/24 Admin access to host
strato-vm 10.0.1.0/24 Direct VM access
openclaw-ai 10.0.3.0/24 AI sandbox tunnel

Seven Security Layers

  1. WireGuard VPN — Encrypted tunnel required for all admin access
  2. Host Firewall (UFW) — Only VPN ports + web traffic open
  3. VPN IP Whitelist — Dashboards restricted to VPN subnets
  4. AI Access Control — iptables chain controlling VM egress
  5. VM Isolation (KVM) — Hardware-level virtualization
  6. Docker Network Isolation — Container egress rules
  7. Authentication — SSH keys, BasicAuth, fail2ban