After seeing the reports about 15,200 exposed OpenClaw control panels, we built a NixOS module that deploys it hardened by default. Gateway auth required, Caddy reverse proxy with auto-TLS, systemd sandboxing (20+ directives), tool allowlists, and fail2ban. One flake import, one rebuild.