Skip to content

Docker Services

All supporting services run as Docker containers on the Strato VPS host and the KVM VM.

Host Container Overview

Container Image Network Ports Purpose
traefik traefik:v3 openclaw-infra (172.20.10.10) 80, 443, 8080 Reverse proxy, TLS
pihole pihole/pihole openclaw-infra (172.20.10.53) 53 DNS, ad-blocking
openclaw-control-center Custom build host 8089 Firewall management
fail2ban-dashboard Custom build openclaw-infra (172.20.10.2) (internal) Ban monitoring
openclaw-docs Custom build (MkDocs Material) openclaw-infra (172.20.10.20) 8000 Infrastructure documentation

VM Container Overview (Strato VM — 192.168.10.10)

All migrated services run on the Strato KVM VM:

Container Image Port Domain
infra-nextcloud nextcloud:latest 8880 cloud.clsxx.de
infra-nextcloud-db mariadb:latest — —
infra-gitea gitea/gitea:latest 3000 git.clsxx.de
infra-gitea-db postgres:15-alpine — —
infra-gitea-runner gitea/act_runner — —
infra-mailserver docker-mailserver:latest 25,143,587,993 —
infra-webmail hardware/rainloop 8888 mail.clsxx.de
infra-portainer portainer-ce:latest 9000 portainer.clsxx.de
part-finder Custom build 8090 parts.clsxx.de
clsxx-dashboard nginx:alpine 8091 dashboard.clsxx.de

Note

The trading stack and worker-remote containers are not listed here — they run separately via their own compose files on the VM.

Docker Network

The openclaw-infra network provides controlled connectivity:

docker network create --driver bridge \
  --subnet 172.20.10.0/24 \
  --gateway 172.20.10.1 \
  openclaw-infra

Why host network for Control Center?

The Control Center needs:

  • NET_ADMIN capability for iptables management
  • Access to the host's network namespace to manage VM traffic
  • Ability to run wg show for VPN monitoring
  • Direct access to port 8089 (routed by Traefik)

Docker Compose Files

Control Center

Location: ~/docker/control-center/docker-compose.yml

services:
  control-center:
    build: .
    container_name: openclaw-control-center
    privileged: true
    pid: host
    network_mode: host
    volumes:
      - ./app:/app/app
      - ./data:/app/data
      - /var/log/vm-firewall.log:/var/log/vm-firewall.log:ro
      - ../infrastructure/traefik/dynamic/vm-services.yml:/app/traefik/vm-services.yml
      - ../infrastructure/traefik/dynamic/host-services.yml:/app/traefik/host-services.yml
      - /opt/secrets:/opt/secrets
      - /home/admin/.ssh/openclaw_vm_strato_key:/root/.ssh/vm-key:ro
    restart: unless-stopped
    environment:
      - VM_IP=192.168.10.10
      - VM_SUBNET=192.168.10.0/24
      - VM_GATEWAY=192.168.10.1
      - VM_BRIDGE=virbr0
      - PIHOLE_URL=http://172.20.10.53
      - PIHOLE_PASSWORD=${PIHOLE_PASSWORD}
      - DOMAIN_SUFFIX=clsxx.de

Note: privileged: true and pid: host are required for nsenter to execute fail2ban-client and other host-level commands inside the host's PID namespace.

Key Docker Capabilities

Capability Why Needed
privileged Full host access for iptables, nsenter, fail2ban-client
pid: host Access to host PID namespace for nsenter commands
NET_ADMIN iptables rule management, WireGuard status
NET_RAW Ping (ICMP) for VM health checks

DOCKER-USER Egress Firewall

The DOCKER-USER iptables chain controls what Docker containers can access outside their network. Managed by /etc/systemd/system/docker-egress.service.

Rule 9 allows Traefik (and other containers on openclaw-infra) to reach the KVM VM at 192.168.10.0/24, which is required for reverse-proxying all VM-hosted subdomains (tokens, trading, git, cloud, etc.).

Without this rule, Traefik returns 504 Gateway Timeout for VM services.

# Verify rules
sudo iptables -L DOCKER-USER -n -v --line-numbers

# Restart after editing the service file
sudo systemctl daemon-reload && sudo systemctl restart docker-egress.service

Container Management

# Start all services
cd ~/docker/control-center && docker compose up -d

# Rebuild after code changes
cd ~/docker/control-center && docker compose up -d --build

# View logs
docker logs openclaw-control-center -f --tail 50

# Restart
docker compose restart

# Stop
docker compose down

Volumes

Mount Container Path Purpose
./app /app/app Application code
./data /app/data Config (rules.json) + audit log
/var/log/vm-firewall.log /var/log/vm-firewall.log (ro) Kernel log for blocked traffic
vm-services.yml /app/traefik/vm-services.yml Traefik VM routes
host-services.yml /app/traefik/host-services.yml Traefik host routes (VPN toggle)
/opt/secrets /opt/secrets Secrets YAML store
vm-key /root/.ssh/vm-key (ro) SSH key for VM deploy