mirror of
https://github.com/openclaw/openclaw.git
synced 2026-10-03 01:29:56 +00:00
Adds the missing reciprocal links and one mis-targeted link fix for the last open `link` audit findings. - Related back-links: system prompt (context engine, timezone), diagnostics flags (gateway diagnostics, gateway troubleshooting), cloud workers (operator scopes), auth credential semantics (secrets, auth storage), agent runtime architecture (agent runtimes), agent runtime workflow (testing), network (remote access, architecture), threat model (gateway security index, network proxy), backups/updating/doctor (database schemas). - docs/security/network-proxy.md gains a Related section. - docs/security/incident-response.md links back to the three sibling pages that already link to it. - docs/concepts/typing-indicators.md links the heartbeat and groups pages that its Defaults section describes. - docs/diagnostics/flags.md links the environment-variable reference from the timeline section that names three OPENCLAW_DIAGNOSTICS_* variables. - docs/concepts/main-session.md names `session.maintenance.maxDiskBytes` and links the maintenance reference instead of stating a bare 10 GB default. - docs/network.md pointed its "Gateway config reference" entry at /gateway/configuration; retargeted to /gateway/configuration-reference. - docs/openclaw-agent-runtime.md merges its References list into Related and keeps the old `#references` anchor as a stub. - Six zh-CN glossary sources added beside their related existing terms.
2.6 KiB
2.6 KiB
| summary | read_when | title | |||
|---|---|---|---|---|---|
| Network hub: gateway surfaces, pairing, discovery, and security |
|
Network |
This hub links the core docs for how OpenClaw connects, pairs, and secures devices across localhost, LAN, and tailnet.
Core model
Most operations flow through the Gateway (openclaw gateway), a single long-running process that owns channel connections and the WebSocket control plane.
- Loopback first: the Gateway WS defaults to
ws://127.0.0.1:18789. Non-loopback binds refuse to start without a valid gateway auth path: shared-secret token/password auth, or a correctly configured non-loopbacktrusted-proxydeployment. - One Gateway per host is recommended. For isolation, run multiple gateways with isolated profiles and ports (Multiple Gateways).
- Hosted widget documents and A2UI renderer assets are served on the same port as the Gateway (
/__openclaw__/canvas/,/__openclaw__/a2ui/), protected by Gateway auth when bound beyond loopback. - Remote access is typically an SSH tunnel or Tailscale VPN (Remote Access).
Key references:
Pairing + identity
- Pairing overview (DM + nodes)
- Gateway-owned node pairing
- Devices CLI (pairing + token rotation)
- Pairing CLI (DM approvals)
Local trust:
- Direct local loopback connects (no forwarded/proxy headers) can be auto-approved for pairing to keep same-host UX smooth.
- OpenClaw also has a narrow backend/container-local self-connect path for trusted shared-secret helper flows.
- Tailnet and LAN clients, including same-host tailnet binds, still require explicit pairing approval.