openclaw/docs/network.md
Vincent Koc 47ff7bfb11
docs: close remaining cross-link gaps across concepts, gateway, and security (#143923)
Adds the missing reciprocal links and one mis-targeted link fix for the
last open `link` audit findings.

- Related back-links: system prompt (context engine, timezone), diagnostics
  flags (gateway diagnostics, gateway troubleshooting), cloud workers
  (operator scopes), auth credential semantics (secrets, auth storage),
  agent runtime architecture (agent runtimes), agent runtime workflow
  (testing), network (remote access, architecture), threat model (gateway
  security index, network proxy), backups/updating/doctor (database schemas).
- docs/security/network-proxy.md gains a Related section.
- docs/security/incident-response.md links back to the three sibling pages
  that already link to it.
- docs/concepts/typing-indicators.md links the heartbeat and groups pages
  that its Defaults section describes.
- docs/diagnostics/flags.md links the environment-variable reference from
  the timeline section that names three OPENCLAW_DIAGNOSTICS_* variables.
- docs/concepts/main-session.md names `session.maintenance.maxDiskBytes` and
  links the maintenance reference instead of stating a bare 10 GB default.
- docs/network.md pointed its "Gateway config reference" entry at
  /gateway/configuration; retargeted to /gateway/configuration-reference.
- docs/openclaw-agent-runtime.md merges its References list into Related and
  keeps the old `#references` anchor as a stub.
- Six zh-CN glossary sources added beside their related existing terms.
2026-09-10 18:34:34 +08:00

2.6 KiB

summary read_when title
Network hub: gateway surfaces, pairing, discovery, and security
You need the network architecture + security overview
You are debugging local vs tailnet access or pairing
You want the canonical list of networking docs
Network

This hub links the core docs for how OpenClaw connects, pairs, and secures devices across localhost, LAN, and tailnet.

Core model

Most operations flow through the Gateway (openclaw gateway), a single long-running process that owns channel connections and the WebSocket control plane.

  • Loopback first: the Gateway WS defaults to ws://127.0.0.1:18789. Non-loopback binds refuse to start without a valid gateway auth path: shared-secret token/password auth, or a correctly configured non-loopback trusted-proxy deployment.
  • One Gateway per host is recommended. For isolation, run multiple gateways with isolated profiles and ports (Multiple Gateways).
  • Hosted widget documents and A2UI renderer assets are served on the same port as the Gateway (/__openclaw__/canvas/, /__openclaw__/a2ui/), protected by Gateway auth when bound beyond loopback.
  • Remote access is typically an SSH tunnel or Tailscale VPN (Remote Access).

Key references:

Pairing + identity

Local trust:

  • Direct local loopback connects (no forwarded/proxy headers) can be auto-approved for pairing to keep same-host UX smooth.
  • OpenClaw also has a narrow backend/container-local self-connect path for trusted shared-secret helper flows.
  • Tailnet and LAN clients, including same-host tailnet binds, still require explicit pairing approval.

Discovery + transports

Nodes + transports

Security