Troubleshooting¶
Common Issues¶
Can't access dashboards¶
Symptoms: Browser shows "connection refused" or times out.
Steps:
-
Verify VPN is connected:
-
Check DNS resolution:
-
Test direct connection:
-
Check Traefik is running:
VM shows "Offline" in Control Center¶
Steps:
-
SSH to host and check VM status:
-
If VM is "shut off", start it:
-
If VM is running but Control Center shows offline, check the bridge:
AI can't access the internet¶
Steps:
- Check AI Access Level — is it "Locked"?
- Verify iptables rules:
- Check if killswitch is active:
- Check DNS from VM:
VPN won't connect¶
Steps:
-
Check WireGuard interface on laptop:
-
Verify endpoint is reachable:
-
Check server-side interface:
(Note: Use public IP for this check since VPN is down) -
Check for key mismatch — verify pubkeys match on both sides.
Control Center container won't start¶
Steps:
-
Check logs:
-
Common issues:
- Port 8089 already in use → another instance running
- Missing volume mounts → check
docker-compose.ymlpaths - Permission denied on iptables → verify
NET_ADMINcapability
Audit log not recording events¶
Steps:
-
Check if file exists and is writable:
-
Check file size (may have hit rotation):
Secrets manager shows "not found" or deploy fails¶
Symptoms: GET /api/secrets returns 404, or deploy shows "ssh: not found".
Steps:
-
Check if
secrets.pyfiles exist in the container: -
If missing, the volume mount is out of sync. Re-sync from the local repo:
-
If "ssh: not found" in container, the Docker image is stale. Rebuild:
-
Clear stale pycache after syncing:
Diagnostic Commands¶
Quick Health Check¶
# Status API
curl -s http://localhost:8089/api/status | python3 -m json.tool
# VPN tunnels
sudo wg show all dump | head -20
# Firewall rules
sudo iptables -L VM_EGRESS -n -v
# Docker containers
docker ps --format "table {{.Names}}\t{{.Status}}\t{{.Ports}}"
# VM status
sudo virsh list --all
# Disk space
df -h /
Log Locations¶
| Log | Location | Access |
|---|---|---|
| Control Center | docker logs openclaw-control-center |
Host |
| Audit events | /app/data/audit.jsonl |
Container |
| Blocked traffic | dmesg \| grep VM_BLOCKED |
Host |
| Traefik | docker logs traefik |
Host |
| Fail2ban | sudo fail2ban-client status |
Host |