openclaw-vps-hardening
Installation
SKILL.md
OpenClaw VPS Server Hardening
Seven-layer defense-in-depth strategy for OpenClaw agents on Hostinger VPS. Built around Cloudflare Tunnel + Access as the primary access layer — port 18789 is never exposed to the internet.
The Strategy (Cloudflare-Based)
Internet → Cloudflare Edge
├── Cloudflare Access (identity check — blocked if unauthenticated)
└── Cloudflare Tunnel (outbound-only from VPS)
└── localhost:18789 (OpenClaw — loopback only)
└── OpenClaw token auth (second factor)
Internet → port 2222 (SSH — key-only, fail2ban)
Internet → port 18789 ✗ (denied by UFW — invisible to port scan)
With Cloudflare active: the VPS has one open port (SSH). Everything else is invisible.