Skip to content

OpenClaw on VPS

A guide to install and run OpenClaw in a private, isolated, and secure manner on a VPS.


What is OpenClaw?

OpenClaw is an open-source personal AI assistant that you can run on your own devices. Unlike traditional chatbots, OpenClaw is an autonomous agent that can execute shell commands, manage files, automate browsers, and connect to multiple channels (WhatsApp, Telegram, Slack, Discord, etc.).

About OpenClaw

OpenClaw (formerly Clawdbot/Moltbot) reached 100k+ stars on GitHub in 2026, becoming one of the fastest-growing projects. It uses the Model Context Protocol (MCP) to integrate with 100+ external services.

Fundamental principle

OpenClaw is not exposed publicly. It must be isolated, restricted, and accessed only through a private network. A misconfigured agent with tool access is a serious security risk.


Who is this guide for?

  • Developers who want an AI agent to automate technical tasks
  • Freelancers and small businesses who need assistance with documents and organization
  • Technical users who value privacy and control over their tools

Knowledge requirements

Concept Required level Where to learn
Terminal/Bash Basic LinuxCommand.org
SSH Basic Section 3 of this guide
Networking (IP, ports) Conceptual DigitalOcean - Understanding IP
VPN Conceptual Explained in section 4
YAML/JSON Basic For configuration files

Estimated time

Section Time Level
1. Preparation 15-20 min Beginner
2. Provision VPS 10-15 min Beginner
3. System security 30-40 min Intermediate
4. Private access 20-30 min Intermediate
5. Install OpenClaw 25-35 min Intermediate
6. LLM APIs 10-15 min Beginner
7. Use cases 15-20 min Intermediate
8. Agent security 30-45 min Advanced
9. Maintenance Reference Intermediate
10. Final checklist 10 min -
Total ~3 hours

What will you achieve?

A private server with OpenClaw that:

  • Is not exposed to the Internet — zero public ports
  • Is only accessible via VPN (Tailscale)
  • Runs with minimal privileges — dedicated user, no root
  • Has limited permissions — only accesses what you configure
  • Complies with security standards — CIS Benchmark, OWASP Agentic Top 10

Target architecture

┌─────────────────────────────────────────────────────────────┐
│                      INTERNET                               │
│                         ❌                                  │
│              (No open ports)                                │
└─────────────────────────────────────────────────────────────┘

┌─────────────────────────────────────────────────────────────┐
│                       YOUR VPS                              │
│  ┌───────────────────────────────────────────────────────┐  │
│  │  Ubuntu 24.04 LTS                                     │  │
│  │  ┌─────────────────────────────────────────────────┐  │  │
│  │  │  Layer 1: UFW Firewall (deny all incoming)      │  │  │
│  │  │  ┌─────────────────────────────────────────┐    │  │  │
│  │  │  │  Layer 2: Tailscale VPN                 │    │  │  │
│  │  │  │  └─> SSH only via Tailscale IP          │    │  │  │
│  │  │  │  └─> Zero-trust ACLs                    │    │  │  │
│  │  │  │  ┌─────────────────────────────────┐    │    │  │  │
│  │  │  │  │  Layer 3: Systemd + Sandbox     │    │    │  │  │
│  │  │  │  │  └─> OpenClaw on localhost      │    │    │  │  │
│  │  │  │  │  └─> Sandbox mode "off" (VPS)    │    │    │  │  │
│  │  │  │  │  └─> Gateway TLS pairing        │    │    │  │  │
│  │  │  │  │  └─> exec-approvals allowlist   │    │    │  │  │
│  │  │  │  │  └─> Restricted sudoers         │    │    │  │  │
│  │  │  │  └─────────────────────────────────┘    │    │  │  │
│  │  │  └─────────────────────────────────────────┘    │  │  │
│  │  └─────────────────────────────────────────────────┘  │  │
│  │  User: openclaw (non-root)                            │  │
│  │  Auditd + AIDE for monitoring                         │  │
│  └───────────────────────────────────────────────────────┘  │
└─────────────────────────────────────────────────────────────┘
          ▲
          │ Tailscale VPN (WireGuard encryption)
          │ Only owner can connect (ACLs)
          ▼
┌─────────────────────────────────────────────────────────────┐
│              YOUR DEVICE                                    │
│  (laptop, mobile — also with Tailscale)                     │
│  SSH + Port forwarding to access OpenClaw                   │
└─────────────────────────────────────────────────────────────┘

Estimated cost

Item Monthly price
VPS (4-8GB RAM, 2 vCPU) $4-12/month
Tailscale (free tier) $0
LLM API $0-80/month
Total ~$4-90/month

Free option

Using Kimi K2.5 on NVIDIA NIM (free) + budget VPS (~$5), you can have OpenClaw running for less than $5/month.


Security standards covered

Standard Coverage Sections
CIS Benchmark Ubuntu 24.04 L1 100% (SSH + kernel hardening) 3
Tailscale Security Hardening 100% 4
OWASP Agentic Top 10 2026 90%+ 5, 7, 8
Systemd Hardening Complete 5

AI agent security risks

AI agents with tools are dangerous if misconfigured

According to security research:

Risk Description Mitigation in this guide
API key leakage Agent can expose credentials SecretRef, output filtering
Prompt injection Malicious inputs manipulate the agent Input validation, guardrails
Malicious skills (ClawHub) 20% of ClawHub skills were malware Strict allowlist, openclaw security audit
ClawJacked (WebSocket) Malicious websites hijack local agents Gateway TLS pairing, loopback binding
Excessive access Filesystem/shell without limits Sandbox "all", least privilege

What NOT to do

Critical mistakes

  • ❌ Run OpenClaw as root
  • ❌ Open ports "just to test"
  • ❌ Use passwords for SSH
  • ❌ Give full filesystem access
  • ❌ Install it on your personal work machine
  • ❌ Install ClawHub skills without reviewing their code (20% were malware)
  • ❌ Connect your personal email to the agent (create a dedicated one)
  • ❌ Use dmPolicy: "open" (allows commands from anyone)
  • ❌ Disable sandbox (mode: "off")
  • ❌ Use curl | bash without verifying the script
  • ❌ Leave Tailscale ACLs on "permit all"

What this guide does NOT cover

  • High availability (HA) or clustering
  • Automated cloud backups (manual only)
  • CI/CD for automatic deployment
  • Multiple agents communicating with each other
  • Kubernetes integration
  • Enterprise production use (requires additional auditing)

Guide structure

# Section Description
1 Preparation Accounts, SSH keys, spending limits
2 Provision VPS Providers, image verification
3 System security User, SSH hardening CIS, firewall, auditd
4 Private access Tailscale, ACLs, remove public SSH
5 Install OpenClaw Node.js, configuration, systemd hardening
6 LLM APIs Configuration, limits, rotation
7 Use cases Practical examples, output filtering
8 Agent security OWASP Agentic, guardrails, AppArmor
9 Maintenance Updates, rotation, backups, DR
10 Final checklist Verification of all controls
- Glossary Term definitions

References


Get started

Next: 1. Preparation — What you need before starting.