openclaw/docs/vps.md
Vincent Koc c0b128344c
docs(gateway,concepts,install,help): fix information-architecture findings (#143977)
Structure-only pass over 50 open `ia` audit rows in docs/gateway/,
docs/concepts/, docs/install/ and docs/help/. No page splits, no page
moves, no URL changes.

On-page structure:
- concepts/multi-user: six H3s inside the 1,288-word per-person accounts section
- concepts/model-failover: one notices section; H2 blocks reordered to
  storage -> rotation -> cooldowns -> fallback -> notices
- concepts/compaction: 'Provider checkpoints' and 'Successor transcripts'
  regrouped under a new 'Provider and engine behavior' H2
- concepts/memory-builtin: 'When to use' moved after 'What it provides'
- concepts/queue: 'Scope and guarantees' split into 'Input durability' and
  'Lanes and scope'
- concepts/session, concepts/session-tool: 'Further reading' merged into 'Related'
- help/debugging: sections reordered (watch mode first); 'Safety notes'
  demoted to H3 under raw stream logging; Node/tsx errors beside VSCode
- help/environment: OPENCLAW_HOME moved under 'Paths and instances'
- help/testing-updates-plugins: 'On this page' section index
- gateway/logging, gateway/multi-tenant-hosting, install/backups: duplicate
  body H1 removed (precedent 204971f2a9), old id kept as an <a id> stub
- install/upstash: 'Next steps'; vps.md: Upstash Box and Render cards

Navigation (docs.json), no URL changes:
- install/nix -> Runtimes; install/ansible -> Hosting > Self-hosted and local
- gateway/clients and gateway/external-apps ahead of gateway/protocol
- gateway/cli-backends, local-models, local-model-services -> new
  'Models and local providers' group
- gateway/heartbeat -> Capabilities > Automation
- gateway/portals -> Web interfaces
- gateway/security/dependency-locking -> Release & CI > Release process
- concepts/typing-indicators -> Messages and delivery
- concepts/usage-tracking, concepts/timezone -> Technical reference

Anchors: 15 changed pages enumerated with parseDocsDocument before and
after. Zero ids lost, zero collisions; 11 added.
2026-09-10 19:20:49 +08:00

6.3 KiB

summary read_when title sidebarTitle
Run OpenClaw on a Linux server or cloud VPS — provider picker, architecture, and tuning
You want to run the Gateway on a Linux server or cloud VPS
You need a quick map of hosting guides
You want generic Linux server tuning for OpenClaw
Linux server Linux Server

Run the OpenClaw Gateway on any Linux server or cloud VPS. This page helps you pick a provider, explains how cloud deployments work, and covers generic Linux tuning that applies everywhere.

Pick a provider

Linux VM Cloud sandbox with preview URLs Simple paid VPS VM with HTTPS proxy Fly Machines Compute Engine Docker on Hetzner VPS VPS with one-click setup One-click, browser setup Always Free ARM tier One-click, browser setup Managed web service ARM self-hosted SSH-managed sandbox box

AWS (EC2 / Lightsail / free tier) also works well. A community video walkthrough is available at x.com/techfrenAJ/status/2014934471095812547 (community resource -- may become unavailable).

How cloud setups work

  • The Gateway runs on the VPS and owns state + workspace.
  • You connect from your laptop or phone via the Control UI or Tailscale/SSH.
  • Treat the VPS as the source of truth and back up the state + workspace regularly.
  • Secure default: keep the Gateway on loopback and access it via SSH tunnel or Tailscale Serve. If you bind to lan or tailnet, the Gateway requires a shared secret (gateway.auth.token or gateway.auth.password) unless auth is delegated to a trusted proxy.

Related pages: Gateway remote access, Platforms hub.

Harden admin access first

Before you install OpenClaw on a public VPS, decide how you want to administer the box itself.

  • For Tailnet-only admin access: install Tailscale first, join the VPS to your tailnet, verify a second SSH session over the Tailscale IP or MagicDNS name, then restrict public SSH.
  • Without Tailscale: apply the equivalent hardening for your SSH path before exposing more services.
  • This is separate from Gateway access. You can still keep OpenClaw bound to loopback and use an SSH tunnel or Tailscale Serve for the dashboard.

Tailscale-specific Gateway options live in Tailscale.

Shared company agent on a VPS

Running a single agent for a team is a valid setup when every user is in the same trust boundary and the agent is business-only.

  • Keep it on a dedicated runtime (VPS/VM/container + dedicated OS user/accounts).
  • Do not sign that runtime into personal Apple/Google accounts or personal browser/password-manager profiles.
  • If users are adversarial to each other, split by gateway/host/OS user.

Security model details: Security.

Using nodes with a VPS

You can keep the Gateway in the cloud and pair nodes on your local devices (Mac/iOS/Android/headless). Nodes provide local screen/camera and system.run capabilities while the Gateway stays in the cloud. A paired Mac can also present hosted widgets in its native panel.

Docs: Nodes, Nodes CLI.

Startup tuning for small VMs and ARM hosts

If CLI commands feel slow on low-power VMs (or ARM hosts), enable Node's module compile cache:

grep -q 'NODE_COMPILE_CACHE=/var/tmp/openclaw-compile-cache' ~/.bashrc || cat >> ~/.bashrc <<'EOF'
export NODE_COMPILE_CACHE=/var/tmp/openclaw-compile-cache
mkdir -p /var/tmp/openclaw-compile-cache
export OPENCLAW_NO_RESPAWN=1
EOF
source ~/.bashrc
  • NODE_COMPILE_CACHE improves repeated command startup times; the first run warms the cache.
  • OPENCLAW_NO_RESPAWN=1 keeps routine Gateway restarts in-process, which avoids extra process handoffs and keeps PID tracking simple on small hosts.
  • For Raspberry Pi specifics, see Raspberry Pi.

systemd tuning checklist (optional)

For VM hosts using systemd, consider:

  • Service env for a stable startup path: OPENCLAW_NO_RESPAWN=1 and NODE_COMPILE_CACHE=/var/tmp/openclaw-compile-cache
  • A longer startup timeout for slow hosts: TimeoutStartSec=90.
  • The managed unit owns the generic restart policy: Restart=always, RestartSec=5.
  • SSD-backed disks for state/cache paths to reduce random-I/O cold-start penalties.

The standard openclaw onboard --install-daemon path installs a systemd user unit; customize only host-specific startup settings with:

systemctl --user edit openclaw-gateway.service
[Service]
Environment=OPENCLAW_NO_RESPAWN=1
Environment=NODE_COMPILE_CACHE=/var/tmp/openclaw-compile-cache
TimeoutStartSec=90

If you deliberately installed a system unit instead, edit it via sudo systemctl edit openclaw-gateway.service.

For the canonical managed unit body and its restart policy, see the Gateway runbook.

For Linux OOM behavior, child process victim selection, and exit 137 diagnostics, see Linux memory pressure and OOM kills.

  • Install overview
  • DigitalOcean
  • Fly.io
  • Hetzner
  • Ansible — automated deployment to remote Debian/Ubuntu servers with Tailscale VPN and firewall isolation
  • Kubernetes — a minimal Kustomize starting point when you run the Gateway on a cluster instead of a single VPS
  • macOS VMs — a sandboxed macOS VM when you need macOS itself (iMessage) rather than a Linux host