Skip to content

KVM Virtual Machine

VM Specifications

Property Value
Name openclaw-debian-home
IP Address 192.168.10.10
Gateway 192.168.10.1 (virbr0)
OS Debian 13 (Trixie)
CPUs 4
RAM 16 GB
Disk 200 GB (qcow2)
Boot UEFI (OVMF)
Bridge virbr0

Users

User Purpose SSH Key
admin Management, sudo access openclaw_vm_strato_key
openclaw AI workspace openclaw_vm_key (local VM)

Installed Software

Software Purpose
Docker CE Container runtime for all services
WireGuard Client for openclaw-ai tunnel
SSH server Remote access (VPN-only)

Directory Structure

Directory Contents
/home/openclaw/stock-trading-ai/ AI Trading platform (docker-compose + source)
/home/openclaw/infrastructure/ Nextcloud, Gitea, Mailserver, Webmail, Portainer
/home/openclaw/services/part-finder/ Part Finder web app
/home/openclaw/services/clsxx-dashboard/ Static dashboard site (nginx)
/opt/openclaw-secrets/<app>/.env Deployed secrets (root:root 600)

Running Services

Infrastructure (/home/openclaw/infrastructure/)

Container Port Domain
infra-nextcloud 8880 cloud.clsxx.de
infra-nextcloud-db — —
infra-gitea 3000, 2222 git.clsxx.de
infra-gitea-db — —
infra-gitea-runner — —
infra-mailserver 25, 143, 587, 993 (DNAT from host)
infra-webmail 8888 mail.clsxx.de
infra-portainer 9000 portainer.clsxx.de

Misc Services (/home/openclaw/services/)

Container Port Domain
part-finder 8090 parts.clsxx.de
clsxx-dashboard 8091 dashboard.clsxx.de

Trading Stack (/home/openclaw/stock-trading-ai/)

The trading platform runs separately via its own compose:

Container Port Domain
trading_app 8000 trading-api.clsxx.de
trading_frontend 5173 trading.clsxx.de
trading_flower 5555 trading-flower.clsxx.de
trading_db 5432 —
trading_redis 6379 —
+ beat, worker, autoheal, pgadmin, test_db, training — —

Network Configuration

The VM's network uses the virbr0 bridge:

VM (192.168.10.10) ←→ virbr0 bridge (192.168.10.1) ←→ Host iptables

DNS

The VM uses the bridge gateway as its DNS server:

/etc/resolv.conf:
nameserver 192.168.10.1

This resolves to Pi-hole (172.20.10.53) via dnsmasq on the host, providing DNS monitoring and ad-blocking.

Internet Access

All VM traffic to destinations outside 192.168.10.0/24 passes through the host's FORWARD chain and the VM_EGRESS iptables chain managed by the Control Center.

Management Commands

Check VM Status

ssh admin@10.0.0.1 "sudo virsh list --all"

Start VM

ssh admin@10.0.0.1 "sudo virsh start openclaw-debian-home"

Stop VM (graceful)

ssh admin@10.0.0.1 "sudo virsh shutdown openclaw-debian-home"

Force Stop VM

ssh admin@10.0.0.1 "sudo virsh destroy openclaw-debian-home"

Console Access

ssh admin@10.0.0.1 "sudo virsh console openclaw-debian-home"

SSH Access

SSH access to the VM is VPN-only — there is no public port forwarding.

# From laptop with vpn_host VPN active
ssh -i ~/.ssh/openclaw_strato_key admin@10.0.0.1 \
  "ssh -i ~/.ssh/openclaw_vm_strato_key admin@192.168.10.10"

From Strato Host (direct)

ssh -o IdentitiesOnly=yes -i ~/.ssh/openclaw_vm_strato_key admin@192.168.10.10

Note: Public port 2222 DNAT was removed. VM SSH is only reachable through the VPN tunnel.