Overview¶
What You're Working With¶
The OpenClaw project is a secure AI development environment hosted on a remote Strato VPS. The core idea is simple:
- An AI assistant runs inside an isolated virtual machine (KVM)
- You control exactly what internet access the AI has
- All admin access is VPN-only — nothing is publicly exposed except web services you explicitly allow
- Every security-relevant action is logged and auditable
Key Concepts¶
The AI Sandbox¶
The AI runs inside a KVM virtual machine at 192.168.10.10. This provides hardware-level isolation — the AI physically cannot access the host machine's filesystem, processes, or network interfaces.
The Control Center¶
The Control Center is a FastAPI web application that manages the VM's network access. It provides:
- Firewall rules via an iptables chain (
VM_EGRESS) - Access level profiles (Locked → Minimal → Development → Unrestricted)
- DNS monitoring via Pi-hole integration
- VPN tunnel status via WireGuard
- Structured audit logging for every action
VPN-Only Access¶
All administrative access (SSH, dashboards) requires an active WireGuard VPN connection. There are three tunnels:
| Tunnel | Subnet | Purpose |
|---|---|---|
strato-host |
10.0.0.0/24 | Admin access to host |
strato-vm |
10.0.1.0/24 | Direct VM access |
openclaw-ai |
10.0.3.0/24 | AI sandbox tunnel |
Seven Security Layers¶
- WireGuard VPN — Encrypted tunnel required for all admin access
- Host Firewall (UFW) — Only VPN ports + web traffic open
- VPN IP Whitelist — Dashboards restricted to VPN subnets
- AI Access Control — iptables chain controlling VM egress
- VM Isolation (KVM) — Hardware-level virtualization
- Docker Network Isolation — Container egress rules
- Authentication — SSH keys, BasicAuth, fail2ban