{"repo":"kapunakap/openclaw-secure-kit","free":true,"listed":false,"github":"https://github.com/kapunakap/openclaw-secure-kit","clone":"git clone https://github.com/kapunakap/openclaw-secure-kit.git","description":"Secure-by-default OpenClaw on Ubuntu, with a verifiable security report","language":"TypeScript","stars":27,"topics":["openclaw","openclaw-security","ai-agents","devsecops","docker","egress-filtering","hardening","nftables","self-hosted","ubuntu"],"license":"MIT","category":"deployment-docker-iac","readme_excerpt":"openclaw-secure-kit Secure-by-default, profile-driven hardening for running OpenClaw on Ubuntu with verifiable egress guardrails . This kit is designed to run after you have a host (Ubuntu + Docker), and before you start using OpenClaw in production. It generates a hardened, reproducible deployment under out/ / and provides a one-command verifier that writes a security report. Note: v1 focuses on DNS allowlisting + host firewall guardrails. It does not guarantee impossible-bypass outbound control (see docs/THREAT MODEL.md ). --- Table of contents - Who this is for - Who it’s not for - Need this deployed for your team? - Demo - Quickstart - How it works - Profiles - Verification ( ocs doctor ) - Security model and caveats - Install / uninstall - Troubleshooting - Docs - Contact - Contributing - Security policy --- Who this is for - You need a hardened deployment posture you can reproduce across Ubuntu hosts using out/ / artifacts. - You need verifier outputs ( security-report.md ) you can hand to security/IT reviewers and internal stakeholders. - You need DNS allowlist + host firewall guardrails without building your own hardening pipeline from scratch. Who it’s not for - You need impossible-bypass outbound control guarantees (including guaranteed direct-to-IP blocking) in v1. - You need cloud provisioning, a multi-tenant control plane, or a web UI in this release. - You need ad-hoc manual setup instead of profile-driven, repeatable operations. --- Need this deployed for your ","default_branch":null,"files":null,"tree":[],"storefront":"/r/kapunakap","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/kapunakap/openclaw-secure-kit/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}