Strato VPS Host¶
Server Details¶
| Property | Value |
|---|---|
| Provider | Strato VPS |
| Public IP | 217.154.228.231 |
| OS | Debian 13 (Trixie) |
| Admin User | admin |
| SSH Access | VPN-only (10.0.0.1 via strato-host tunnel) |
Installed Software¶
| Software | Version | Purpose |
|---|---|---|
| Docker CE | 27+ | Container runtime |
| Docker Compose | v2 | Container orchestration |
| WireGuard | Latest | VPN tunnels |
| UFW | Latest | Host firewall |
| KVM/libvirt | Latest | VM hypervisor |
| fail2ban | Latest | Intrusion prevention |
Directory Structure¶
/home/admin/
├── docker/
│ ├── control-center/ # Control Center (new, active)
│ │ ├── app/ # FastAPI application
│ │ ├── data/ # rules.json, audit.jsonl
│ │ ├── Dockerfile
│ │ └── docker-compose.yml
│ ├── vm-firewall/ # Old Control Center (backup)
│ ├── infrastructure/
│ │ ├── traefik/
│ │ │ ├── traefik.yml # Static config
│ │ │ ├── dynamic/
│ │ │ │ ├── middlewares.yml # BasicAuth, IP whitelist
│ │ │ │ └── vm-services.yml # VM routes (managed by CC)
│ │ │ ├── acme.json # Let's Encrypt certs
│ │ │ └── docker-compose.yml
│ │ ├── pihole/
│ │ │ └── docker-compose.yml
│ │ └── fail2ban-dashboard/
│ │ └── docker-compose.yml
│ └── .env # Shared environment variables
WireGuard Configuration¶
Server-side configs are at /etc/wireguard/:
| Config File | Interface | Listen Port |
|---|---|---|
strato-host.conf |
strato-host | 51820 |
strato-vm.conf |
strato-vm | 51821 |
openclaw-ai.conf |
openclaw-ai | 51822 |
All interfaces are managed by wg-quick and enabled at boot via systemd:
sudo systemctl enable wg-quick@strato-host
sudo systemctl enable wg-quick@strato-vm
sudo systemctl enable wg-quick@openclaw-ai
UFW Rules¶
sudo ufw status
# Status: active
# 80/tcp ALLOW Anywhere
# 443/tcp ALLOW Anywhere
# 51820/udp ALLOW Anywhere
# 51821/udp ALLOW Anywhere
# 51822/udp ALLOW Anywhere
SSH (port 22) is allowed only from VPN subnets via UFW rules or AllowedIPs.
Mail Port Forwarding (DNAT)¶
Mail ports are forwarded from the host to the KVM VM using persistent DNAT rules in /etc/ufw/before.rules:
| Port | Protocol | Service | Destination |
|---|---|---|---|
| 25 | TCP | SMTP | 192.168.10.10:25 |
| 143 | TCP | IMAP | 192.168.10.10:143 |
| 587 | TCP | SMTP Submission | 192.168.10.10:587 |
| 993 | TCP | IMAPS | 192.168.10.10:993 |
The rules consist of two parts in /etc/ufw/before.rules:
*nattable — DNAT rules that redirect incoming traffic to the VM*filtertable (ufw-before-forwardchain) — FORWARD rules that allow the DNATed traffic through
Fail2ban jails (postfix and dovecot) are active on the host to protect against brute-force attacks on mail services.
SSH Configuration¶
Key hardening measures in /etc/ssh/sshd_config:
PasswordAuthentication noPermitRootLogin noPubkeyAuthentication yesListenAddress 10.0.0.1(VPN only)