Skip to content

Deployment

Control Center Deployment

Prerequisites

  • SSH access to Strato host via VPN
  • Docker and Docker Compose on the host

Deploy from Local Machine

# 1. Copy files to host
scp -o IdentitiesOnly=yes -i ~/.ssh/openclaw_strato_key \
  -r control-center admin@10.0.0.1:~/docker/

# 2. SSH to host
ssh -o IdentitiesOnly=yes -i ~/.ssh/openclaw_strato_key admin@10.0.0.1

# 3. Build and start
cd ~/docker/control-center
docker compose up -d --build

# 4. Verify
docker logs openclaw-control-center --tail 20
curl -s http://localhost:8089/api/status | python3 -m json.tool

Update Existing Deployment

# From local machine: sync files
scp -o IdentitiesOnly=yes -i ~/.ssh/openclaw_strato_key \
  -r control-center/app admin@10.0.0.1:~/docker/control-center/

# On host: rebuild
ssh admin@10.0.0.1 "cd ~/docker/control-center && docker compose up -d --build"

Rollback

The old Control Center is preserved at ~/docker/vm-firewall/:

# Stop new
cd ~/docker/control-center && docker compose down

# Start old
cd ~/docker/vm-firewall && docker compose up -d

Documentation Deployment

Deploy Documentation Service

# Copy docs to host
scp -o IdentitiesOnly=yes -i ~/.ssh/openclaw_strato_key \
  -r docs admin@10.0.0.1:~/docker/

# Start MkDocs container
ssh admin@10.0.0.1 "cd ~/docker/docs && docker compose up -d --build"

Access

Documentation is available at https://docs.clsxx.de (VPN + BasicAuth required).

Environment Variables

Create/update ~/docker/.env on the host:

PIHOLE_PASSWORD=<pihole-admin-password>

Verification Checklist

After deployment, verify:

  • [ ] docker ps shows openclaw-control-center running
  • [ ] curl http://localhost:8089/api/status returns valid JSON
  • [ ] https://firewall.clsxx.de loads the UI (via VPN)
  • [ ] VPN status shows all 3 tunnels
  • [ ] Audit log shows system.started event
  • [ ] Firewall rules are applied (check iptables -L VM_EGRESS -n)