Skip to content

Troubleshooting

Common Issues

Can't access dashboards

Symptoms: Browser shows "connection refused" or times out.

Steps:

  1. Verify VPN is connected:

    sudo wg show vpn_host
    # Should show a recent handshake
    

  2. Check DNS resolution:

    dig firewall.clsxx.de
    # Should resolve to 10.0.0.1
    

  3. Test direct connection:

    curl -k https://10.0.0.1:443 -H "Host: firewall.clsxx.de"
    

  4. Check Traefik is running:

    ssh admin@10.0.0.1 "docker ps --filter name=traefik"
    

VM shows "Offline" in Control Center

Steps:

  1. SSH to host and check VM status:

    ssh admin@10.0.0.1 "sudo virsh list --all"
    

  2. If VM is "shut off", start it:

    ssh admin@10.0.0.1 "sudo virsh start openclaw-debian-home"
    

  3. If VM is running but Control Center shows offline, check the bridge:

    ssh admin@10.0.0.1 "ping -c 2 192.168.10.10"
    

AI can't access the internet

Steps:

  1. Check AI Access Level — is it "Locked"?
  2. Verify iptables rules:
    ssh admin@10.0.0.1 "sudo iptables -L VM_EGRESS -n -v"
    
  3. Check if killswitch is active:
    curl -s http://localhost:8089/api/rules | python3 -c "import sys,json; d=json.load(sys.stdin); print('killswitch:', d['killswitch'])"
    
  4. Check DNS from VM:
    ssh admin@192.168.10.10 "dig google.com"
    

VPN won't connect

Steps:

  1. Check WireGuard interface on laptop:

    sudo wg show vpn_host
    

  2. Verify endpoint is reachable:

    nc -zvu 217.154.228.231 51820
    

  3. Check server-side interface:

    ssh admin@217.154.228.231 "sudo wg show strato-host"
    
    (Note: Use public IP for this check since VPN is down)

  4. Check for key mismatch — verify pubkeys match on both sides.

Control Center container won't start

Steps:

  1. Check logs:

    docker logs openclaw-control-center 2>&1 | tail -30
    

  2. Common issues:

  3. Port 8089 already in use → another instance running
  4. Missing volume mounts → check docker-compose.yml paths
  5. Permission denied on iptables → verify NET_ADMIN capability

Audit log not recording events

Steps:

  1. Check if file exists and is writable:

    docker exec openclaw-control-center ls -la /app/data/audit.jsonl
    

  2. Check file size (may have hit rotation):

    docker exec openclaw-control-center wc -l /app/data/audit.jsonl
    

Secrets manager shows "not found" or deploy fails

Symptoms: GET /api/secrets returns 404, or deploy shows "ssh: not found".

Steps:

  1. Check if secrets.py files exist in the container:

    docker exec openclaw-control-center ls /app/app/routers/secrets.py /app/app/services/secrets.py
    

  2. If missing, the volume mount is out of sync. Re-sync from the local repo:

    cd ~/clsxx-openclaw-project/control-center
    tar czf - --exclude='__pycache__' app/ | ssh admin@10.0.0.1 "cd ~/docker/control-center && tar xzf -"
    

  3. If "ssh: not found" in container, the Docker image is stale. Rebuild:

    ssh admin@10.0.0.1 "cd ~/docker/control-center && docker compose down && docker compose build --no-cache && docker compose up -d"
    

  4. Clear stale pycache after syncing:

    ssh admin@10.0.0.1 "sudo rm -rf ~/docker/control-center/app/{,routers/,services/}__pycache__"
    docker compose restart
    


Diagnostic Commands

Quick Health Check

# Status API
curl -s http://localhost:8089/api/status | python3 -m json.tool

# VPN tunnels
sudo wg show all dump | head -20

# Firewall rules
sudo iptables -L VM_EGRESS -n -v

# Docker containers
docker ps --format "table {{.Names}}\t{{.Status}}\t{{.Ports}}"

# VM status
sudo virsh list --all

# Disk space
df -h /

Log Locations

Log Location Access
Control Center docker logs openclaw-control-center Host
Audit events /app/data/audit.jsonl Container
Blocked traffic dmesg \| grep VM_BLOCKED Host
Traefik docker logs traefik Host
Fail2ban sudo fail2ban-client status Host