Skip to content

Emergency Procedures

Immediate Response

🚨 Emergency Stop (AI doing something dangerous)

  1. Hit "Emergency Stop" on the Control Center Dashboard
  2. Or via API: curl -X POST http://localhost:8089/api/killswitch
  3. This immediately drops ALL VM traffic

  4. Check what the AI was doing:

  5. DNS Monitor: What domains was it querying?
  6. Audit Log: What recent actions were taken?
  7. Debug tab: Check blocked traffic log

  8. Investigate on the VM:

    ssh admin@192.168.10.10
    docker ps           # What containers are running?
    ss -tlnp            # What's listening?
    ps aux              # Active processes
    

  9. If needed, shut down the VM entirely:

    ssh admin@10.0.0.1 "sudo virsh shutdown openclaw-debian-home"
    

🚨 VPN Compromised (suspected key leak)

  1. Rotate all WireGuard keys immediately — See Key Rotation

  2. Check for unauthorized connections:

    ssh admin@10.0.0.1 "sudo wg show all"
    # Look for unexpected endpoints or peers
    

  3. Review audit log for suspicious actions:

    ssh admin@10.0.0.1 "cat ~/docker/control-center/data/audit.jsonl | python3 -m json.tool"
    

🚨 Host Compromised

  1. Do NOT trust the VPN — Connect via Strato's web console or direct SSH:

    ssh -o IdentitiesOnly=yes -i ~/.ssh/openclaw_strato_key admin@217.154.228.231
    
    (This only works if SSH is listening on public IP, which it normally isn't)

  2. Use Strato's rescue system if you can't SSH in

  3. Check for unauthorized changes:

    last -20                        # Login history
    sudo cat /var/log/auth.log | tail -50  # Auth log
    sudo fail2ban-client status     # Ban activity
    docker ps -a                    # Unknown containers?
    

  4. Consider rebuilding — If compromise is confirmed, rebuild the host from scratch

Recovery After Emergency Stop

  1. Review what happened (audit log, DNS queries, blocked traffic)
  2. Determine appropriate access level
  3. Apply the correct profile:
    curl -X POST http://localhost:8089/api/profile/locked
    
  4. Deactivate killswitch:
    curl -X POST http://localhost:8089/api/killswitch
    

Contact Information

All dashboards are accessible at:

URL Purpose
https://firewall.clsxx.de Control Center
https://pihole.clsxx.de DNS monitoring
https://fail2ban.clsxx.de Ban monitoring
https://docs.clsxx.de This documentation