Emergency Procedures¶
Immediate Response¶
🚨 Emergency Stop (AI doing something dangerous)¶
- Hit "Emergency Stop" on the Control Center Dashboard
- Or via API:
curl -X POST http://localhost:8089/api/killswitch -
This immediately drops ALL VM traffic
-
Check what the AI was doing:
- DNS Monitor: What domains was it querying?
- Audit Log: What recent actions were taken?
-
Debug tab: Check blocked traffic log
-
Investigate on the VM:
-
If needed, shut down the VM entirely:
🚨 VPN Compromised (suspected key leak)¶
-
Rotate all WireGuard keys immediately — See Key Rotation
-
Check for unauthorized connections:
-
Review audit log for suspicious actions:
🚨 Host Compromised¶
-
Do NOT trust the VPN — Connect via Strato's web console or direct SSH:
(This only works if SSH is listening on public IP, which it normally isn't) -
Use Strato's rescue system if you can't SSH in
-
Check for unauthorized changes:
-
Consider rebuilding — If compromise is confirmed, rebuild the host from scratch
Recovery After Emergency Stop¶
- Review what happened (audit log, DNS queries, blocked traffic)
- Determine appropriate access level
- Apply the correct profile:
- Deactivate killswitch:
Contact Information¶
All dashboards are accessible at:
| URL | Purpose |
|---|---|
https://firewall.clsxx.de |
Control Center |
https://pihole.clsxx.de |
DNS monitoring |
https://fail2ban.clsxx.de |
Ban monitoring |
https://docs.clsxx.de |
This documentation |