Prerequisites
Required Infrastructure
| Component |
Requirement |
| VPS |
Strato VPS or equivalent (dedicated server with KVM support) |
| OS |
Debian 13 (Trixie) on host and VM |
| Docker |
Docker CE 27+ with Compose v2 |
| WireGuard |
Installed on host, VMs, and admin laptop |
| Domain |
Wildcard DNS for *.clsxx.de pointing to VPS IP |
Client Requirements
Admin Laptop
- WireGuard client (NetworkManager integration or standalone)
- SSH client with key-based authentication
- Web browser for dashboard access
- Three WireGuard configuration files (provided during setup)
SSH Keys
| Key File |
Purpose |
~/.ssh/openclaw_strato_key |
Strato VPS host access |
~/.ssh/openclaw_vm_strato_key |
Strato KVM VM access (via host) |
~/.ssh/openclaw_vm_key |
Local VM access |
WireGuard Configs
| Config |
Local Path |
VPN Subnet |
| Admin VPN |
/etc/wireguard/vpn_host.conf |
10.0.0.0/24 |
| VM Access |
/etc/wireguard/vpn_vm.conf |
10.0.1.0/24 |
Network Requirements
The following ports must be open on the VPS:
| Port |
Protocol |
Purpose |
| 80 |
TCP |
HTTP → HTTPS redirect |
| 443 |
TCP |
HTTPS (Traefik) |
| 51820 |
UDP |
WireGuard: strato-host (Admin VPN) |
| 51821 |
UDP |
WireGuard: strato-vm (VM Access VPN) |
| 51822 |
UDP |
WireGuard: openclaw-ai (AI Tunnel) |