Docker Services¶
All supporting services run as Docker containers on the Strato VPS host and the KVM VM.
Host Container Overview¶
| Container | Image | Network | Ports | Purpose |
|---|---|---|---|---|
traefik |
traefik:v3 | openclaw-infra (172.20.10.10) | 80, 443, 8080 | Reverse proxy, TLS |
pihole |
pihole/pihole | openclaw-infra (172.20.10.53) | 53 | DNS, ad-blocking |
openclaw-control-center |
Custom build | host | 8089 | Firewall management |
fail2ban-dashboard |
Custom build | openclaw-infra (172.20.10.2) | (internal) | Ban monitoring |
openclaw-docs |
Custom build (MkDocs Material) | openclaw-infra (172.20.10.20) | 8000 | Infrastructure documentation |
VM Container Overview (Strato VM — 192.168.10.10)¶
All migrated services run on the Strato KVM VM:
| Container | Image | Port | Domain |
|---|---|---|---|
infra-nextcloud |
nextcloud:latest | 8880 | cloud.clsxx.de |
infra-nextcloud-db |
mariadb:latest | — | — |
infra-gitea |
gitea/gitea:latest | 3000 | git.clsxx.de |
infra-gitea-db |
postgres:15-alpine | — | — |
infra-gitea-runner |
gitea/act_runner | — | — |
infra-mailserver |
docker-mailserver:latest | 25,143,587,993 | — |
infra-webmail |
hardware/rainloop | 8888 | mail.clsxx.de |
infra-portainer |
portainer-ce:latest | 9000 | portainer.clsxx.de |
part-finder |
Custom build | 8090 | parts.clsxx.de |
clsxx-dashboard |
nginx:alpine | 8091 | dashboard.clsxx.de |
Note
The trading stack and worker-remote containers are not listed here — they run separately via their own compose files on the VM.
Docker Network¶
The openclaw-infra network provides controlled connectivity:
docker network create --driver bridge \
--subnet 172.20.10.0/24 \
--gateway 172.20.10.1 \
openclaw-infra
Why host network for Control Center?¶
The Control Center needs:
NET_ADMINcapability for iptables management- Access to the host's network namespace to manage VM traffic
- Ability to run
wg showfor VPN monitoring - Direct access to port 8089 (routed by Traefik)
Docker Compose Files¶
Control Center¶
Location: ~/docker/control-center/docker-compose.yml
services:
control-center:
build: .
container_name: openclaw-control-center
privileged: true
pid: host
network_mode: host
volumes:
- ./app:/app/app
- ./data:/app/data
- /var/log/vm-firewall.log:/var/log/vm-firewall.log:ro
- ../infrastructure/traefik/dynamic/vm-services.yml:/app/traefik/vm-services.yml
- ../infrastructure/traefik/dynamic/host-services.yml:/app/traefik/host-services.yml
- /opt/secrets:/opt/secrets
- /home/admin/.ssh/openclaw_vm_strato_key:/root/.ssh/vm-key:ro
restart: unless-stopped
environment:
- VM_IP=192.168.10.10
- VM_SUBNET=192.168.10.0/24
- VM_GATEWAY=192.168.10.1
- VM_BRIDGE=virbr0
- PIHOLE_URL=http://172.20.10.53
- PIHOLE_PASSWORD=${PIHOLE_PASSWORD}
- DOMAIN_SUFFIX=clsxx.de
Note: privileged: true and pid: host are required for nsenter to execute
fail2ban-client and other host-level commands inside the host's PID namespace.
Key Docker Capabilities¶
| Capability | Why Needed |
|---|---|
privileged |
Full host access for iptables, nsenter, fail2ban-client |
pid: host |
Access to host PID namespace for nsenter commands |
NET_ADMIN |
iptables rule management, WireGuard status |
NET_RAW |
Ping (ICMP) for VM health checks |
DOCKER-USER Egress Firewall¶
The DOCKER-USER iptables chain controls what Docker containers can access outside their network.
Managed by /etc/systemd/system/docker-egress.service.
Rule 9 allows Traefik (and other containers on openclaw-infra) to reach the KVM VM at 192.168.10.0/24,
which is required for reverse-proxying all VM-hosted subdomains (tokens, trading, git, cloud, etc.).
Without this rule, Traefik returns 504 Gateway Timeout for VM services.
# Verify rules
sudo iptables -L DOCKER-USER -n -v --line-numbers
# Restart after editing the service file
sudo systemctl daemon-reload && sudo systemctl restart docker-egress.service
Container Management¶
# Start all services
cd ~/docker/control-center && docker compose up -d
# Rebuild after code changes
cd ~/docker/control-center && docker compose up -d --build
# View logs
docker logs openclaw-control-center -f --tail 50
# Restart
docker compose restart
# Stop
docker compose down
Volumes¶
| Mount | Container Path | Purpose |
|---|---|---|
./app |
/app/app |
Application code |
./data |
/app/data |
Config (rules.json) + audit log |
/var/log/vm-firewall.log |
/var/log/vm-firewall.log (ro) |
Kernel log for blocked traffic |
vm-services.yml |
/app/traefik/vm-services.yml |
Traefik VM routes |
host-services.yml |
/app/traefik/host-services.yml |
Traefik host routes (VPN toggle) |
/opt/secrets |
/opt/secrets |
Secrets YAML store |
vm-key |
/root/.ssh/vm-key (ro) |
SSH key for VM deploy |