Deployment Overview of OpenClaw on Server¶
Prerequisites and Basic Requirements¶
To ensure a successful deployment, the server must meet the following requirements:
-
Operating System: Debian 11+ or Ubuntu 20.04+.
-
Privileges: Root or sudo access is required for package installation and service management.
-
Dependencies: The system requires Node.js (version 24.16+ or 26.1+) to avoid NUL truncation issues in SQLite.
-
Network/Ports:
-
Port
80(HTTP) for Let's Encrypt challenges and redirection. -
Port
443(HTTPS) for secure web access. -
Port
18789(Gateway) used by the application internally.
FQDN of the final panel on the hostkey.in domain¶
The application is accessible via a specific subdomain generated based on the server ID.
| Parameter | Value |
|---|---|
| Prefix | openclaw |
| Domain | hostkey.in |
| Full template | openclaw{Server_ID_from_Invapi}.hostkey.in |
File and Directory Structure¶
The deployment utilizes several specific directories for configuration, data, and security:
-
/home/openclaw: Home directory for the application user. -
/home/openclaw/.openclaw: Application configuration directory. -
/root/nginx: Contains the Docker Compose file for the reverse proxy. -
/data/nginx: Stores Nginx user configurations. -
/data/nginx/user_conf.d: Directory for site-specific Nginx configuration files. -
/data/nginx/letsencrypt/.well-known/acme-challenge: Used for SSL certificate validation. -
/etc/systemd/system/openclaw-gateway.service: Systemd service unit file.
Application Installation Process¶
The installation follows a multi-step process involving system preparation, runtime environment setup, and application bootstrapping:
-
System Preparation: The package manager is cleaned of conflicting NodeSource repositories to ensure stability. Base packages including
ca-certificates,curl,gnupg,sudo, anddbus-user-sessionare installed. -
Runtime Environment Setup:
-
A dedicated system user
openclawis created with a restricted shell and lingering enabled to ensure background processes persist after logout. -
NodeSource repositories are added to provide the required Node.js version.
-
pnpmis installed globally vianpm. -
Application Installation: The OpenClaw application is installed globally for the
openclawuser usingpnpm install -g openclaw@latest. -
Configuration and Bootstrapping:
-
An automated onboarding process is executed via
openclaw onboardto initialize the local database and configuration settings. -
The gateway configuration is patched to allow the specific FQDN as a trusted origin for the Control UI.
-
Service Integration: A systemd service unit is created and enabled to manage the OpenClaw Gateway process.
Access Rights and Security¶
Security is enforced through several layers:
-
User Isolation: The application runs under a dedicated
openclawuser with limited permissions. -
Firewall Configuration: If
ufwis present, rules are automatically added to allow incoming traffic on ports80/tcpand443/tcp. -
SSL/TLS: All web traffic is forced from HTTP to HTTPS via Nginx redirection.
-
Secure Path: The system's
secure_pathin sudoers is updated to include the application's specific binary paths for theopenclawuser.
Databases¶
The application uses a local database (SQLite) managed by the OpenClaw process. Data is stored within the application's home directory under /home/openclaw/.openclaw.
Docker Containers and Their Deployment¶
The deployment utilizes one primary container to handle SSL certificates and reverse proxying:
-
Nginx Certbot Container
-
Image:
jonasal/nginx-certbot:latest -
Ports: Maps host ports
80and443to the container. -
Volumes:
-
nginx_secrets:/etc/letsencrypt(External volume for SSL certificates) -
/data/nginx/user_conf.d:/etc/nginx/user_conf.d(Custom Nginx configurations) -
Environment Variables: Configured via
/data/nginx/nginx-certbot.env. -
Restart Policy:
unless-stopped -
Network Mode:
host
Custom Scripts and Additional Setup¶
Several automated actions are performed during the setup:
-
Gateway Token Generation: A secure 48-character token is generated and stored in
/root/openclaw-gateway-token.txt. This token is used to authenticate the gateway for administrative tasks. -
Nginx Configuration Generation: A custom Nginx configuration file is dynamically created in
/data/nginx/user_conf.d/to proxy requests from port 443 to the local OpenClaw gateway on port18789.
Application Update Instructions¶
To update the main application, the following steps should be taken:
-
Application Core: Since the application is installed via
pnpm, you can update it by running the global install command again as theopenclawuser: -
Reverse Proxy: To update the Nginx Certbot container, navigate to
/root/nginxand run:
Location of Configuration Files and Data¶
| Component | Path |
|---|---|
| Application Config | /home/openclaw/.openclaw |
| Nginx User Configs | /data/nginx/user_conf.d/ |
| SSL Certificates | Managed via Docker volume nginx_secrets |
| Gateway Token | /root/openclaw-gateway-token.txt |
Available Ports for Connection¶
-
HTTPS (Web Panel): Port
443(via Nginx proxy). -
HTTP (Redirect): Port
80. -
Internal Gateway: Port
18789(Localhost only).
Starting and Stopping the Application¶
The application is managed via systemd:
-
Start OpenClaw Gateway:
-
Stop OpenClaw Gateway:
-
Restart OpenClaw Gateway:
Proxy Servers¶
The application uses an Nginx reverse proxy container (jonasal/nginx-certbot) to handle SSL termination via Let's Encrypt. The proxy is configured to:
-
Handle ACME challenges for automated certificate renewal.
-
Redirect all HTTP traffic to HTTPS.
-
Proxy WebSocket and standard HTTP requests to the local OpenClaw gateway.