OpenClaw on VPS¶
A guide to install and run OpenClaw in a private, isolated, and secure manner on a VPS.
What is OpenClaw?¶
OpenClaw is an open-source personal AI assistant that you can run on your own devices. Unlike traditional chatbots, OpenClaw is an autonomous agent that can execute shell commands, manage files, automate browsers, and connect to multiple channels (WhatsApp, Telegram, Slack, Discord, etc.).
About OpenClaw
OpenClaw (formerly Clawdbot/Moltbot) reached 100k+ stars on GitHub in 2026, becoming one of the fastest-growing projects. It uses the Model Context Protocol (MCP) to integrate with 100+ external services.
Fundamental principle
OpenClaw is not exposed publicly. It must be isolated, restricted, and accessed only through a private network. A misconfigured agent with tool access is a serious security risk.
Who is this guide for?¶
- Developers who want an AI agent to automate technical tasks
- Freelancers and small businesses who need assistance with documents and organization
- Technical users who value privacy and control over their tools
Knowledge requirements¶
| Concept | Required level | Where to learn |
|---|---|---|
| Terminal/Bash | Basic | LinuxCommand.org |
| SSH | Basic | Section 3 of this guide |
| Networking (IP, ports) | Conceptual | DigitalOcean - Understanding IP |
| VPN | Conceptual | Explained in section 4 |
| YAML/JSON | Basic | For configuration files |
Estimated time¶
| Section | Time | Level |
|---|---|---|
| 1. Preparation | 15-20 min | Beginner |
| 2. Provision VPS | 10-15 min | Beginner |
| 3. System security | 30-40 min | Intermediate |
| 4. Private access | 20-30 min | Intermediate |
| 5. Install OpenClaw | 25-35 min | Intermediate |
| 6. LLM APIs | 10-15 min | Beginner |
| 7. Use cases | 15-20 min | Intermediate |
| 8. Agent security | 30-45 min | Advanced |
| 9. Maintenance | Reference | Intermediate |
| 10. Final checklist | 10 min | - |
| Total | ~3 hours |
What will you achieve?¶
A private server with OpenClaw that:
- Is not exposed to the Internet — zero public ports
- Is only accessible via VPN (Tailscale)
- Runs with minimal privileges — dedicated user, no root
- Has limited permissions — only accesses what you configure
- Complies with security standards — CIS Benchmark, OWASP Agentic Top 10
Target architecture¶
┌─────────────────────────────────────────────────────────────┐
│ INTERNET │
│ ❌ │
│ (No open ports) │
└─────────────────────────────────────────────────────────────┘
┌─────────────────────────────────────────────────────────────┐
│ YOUR VPS │
│ ┌───────────────────────────────────────────────────────┐ │
│ │ Ubuntu 24.04 LTS │ │
│ │ ┌─────────────────────────────────────────────────┐ │ │
│ │ │ Layer 1: UFW Firewall (deny all incoming) │ │ │
│ │ │ ┌─────────────────────────────────────────┐ │ │ │
│ │ │ │ Layer 2: Tailscale VPN │ │ │ │
│ │ │ │ └─> SSH only via Tailscale IP │ │ │ │
│ │ │ │ └─> Zero-trust ACLs │ │ │ │
│ │ │ │ ┌─────────────────────────────────┐ │ │ │ │
│ │ │ │ │ Layer 3: Systemd + Sandbox │ │ │ │ │
│ │ │ │ │ └─> OpenClaw on localhost │ │ │ │ │
│ │ │ │ │ └─> Sandbox mode "off" (VPS) │ │ │ │ │
│ │ │ │ │ └─> Gateway TLS pairing │ │ │ │ │
│ │ │ │ │ └─> exec-approvals allowlist │ │ │ │ │
│ │ │ │ │ └─> Restricted sudoers │ │ │ │ │
│ │ │ │ └─────────────────────────────────┘ │ │ │ │
│ │ │ └─────────────────────────────────────────┘ │ │ │
│ │ └─────────────────────────────────────────────────┘ │ │
│ │ User: openclaw (non-root) │ │
│ │ Auditd + AIDE for monitoring │ │
│ └───────────────────────────────────────────────────────┘ │
└─────────────────────────────────────────────────────────────┘
▲
│ Tailscale VPN (WireGuard encryption)
│ Only owner can connect (ACLs)
▼
┌─────────────────────────────────────────────────────────────┐
│ YOUR DEVICE │
│ (laptop, mobile — also with Tailscale) │
│ SSH + Port forwarding to access OpenClaw │
└─────────────────────────────────────────────────────────────┘
Estimated cost¶
| Item | Monthly price |
|---|---|
| VPS (4-8GB RAM, 2 vCPU) | $4-12/month |
| Tailscale (free tier) | $0 |
| LLM API | $0-80/month |
| Total | ~$4-90/month |
Free option
Using Kimi K2.5 on NVIDIA NIM (free) + budget VPS (~$5), you can have OpenClaw running for less than $5/month.
Security standards covered¶
| Standard | Coverage | Sections |
|---|---|---|
| CIS Benchmark Ubuntu 24.04 L1 | 100% (SSH + kernel hardening) | 3 |
| Tailscale Security Hardening | 100% | 4 |
| OWASP Agentic Top 10 2026 | 90%+ | 5, 7, 8 |
| Systemd Hardening | Complete | 5 |
AI agent security risks¶
AI agents with tools are dangerous if misconfigured
According to security research:
| Risk | Description | Mitigation in this guide |
|---|---|---|
| API key leakage | Agent can expose credentials | SecretRef, output filtering |
| Prompt injection | Malicious inputs manipulate the agent | Input validation, guardrails |
| Malicious skills (ClawHub) | 20% of ClawHub skills were malware | Strict allowlist, openclaw security audit |
| ClawJacked (WebSocket) | Malicious websites hijack local agents | Gateway TLS pairing, loopback binding |
| Excessive access | Filesystem/shell without limits | Sandbox "all", least privilege |
What NOT to do¶
Critical mistakes
- ❌ Run OpenClaw as root
- ❌ Open ports "just to test"
- ❌ Use passwords for SSH
- ❌ Give full filesystem access
- ❌ Install it on your personal work machine
- ❌ Install ClawHub skills without reviewing their code (20% were malware)
- ❌ Connect your personal email to the agent (create a dedicated one)
- ❌ Use
dmPolicy: "open"(allows commands from anyone) - ❌ Disable sandbox (
mode: "off") - ❌ Use
curl | bashwithout verifying the script - ❌ Leave Tailscale ACLs on "permit all"
What this guide does NOT cover¶
- High availability (HA) or clustering
- Automated cloud backups (manual only)
- CI/CD for automatic deployment
- Multiple agents communicating with each other
- Kubernetes integration
- Enterprise production use (requires additional auditing)
Guide structure¶
| # | Section | Description |
|---|---|---|
| 1 | Preparation | Accounts, SSH keys, spending limits |
| 2 | Provision VPS | Providers, image verification |
| 3 | System security | User, SSH hardening CIS, firewall, auditd |
| 4 | Private access | Tailscale, ACLs, remove public SSH |
| 5 | Install OpenClaw | Node.js, configuration, systemd hardening |
| 6 | LLM APIs | Configuration, limits, rotation |
| 7 | Use cases | Practical examples, output filtering |
| 8 | Agent security | OWASP Agentic, guardrails, AppArmor |
| 9 | Maintenance | Updates, rotation, backups, DR |
| 10 | Final checklist | Verification of all controls |
| - | Glossary | Term definitions |
References¶
- OpenClaw - Official Documentation
- OpenClaw - Security
- OpenClaw - Hardening Guide (Nebius)
- CIS Ubuntu Linux 24.04 LTS Benchmark
- Tailscale Security Hardening
- OWASP Top 10 for Agentic Applications 2026
- OWASP Top 10 for LLM Applications 2025
- NIST AI Agent Standards Initiative (2026)
- systemd Hardening
- Cisco - AI Agent Security Risks
- ClawHub Supply Chain Attack (The Hacker News)
- Hetzner Cloud Review 2026 (Better Stack)
- SSH Hardening Guides (ssh-audit)
Get started¶
Next: 1. Preparation — What you need before starting.