OpenClaw deployment guide
Deploy OpenClaw on a VPS and own your AI agent infrastructure
Short answer
An OpenClaw gateway running behind HTTPS on your domain, connected to Telegram or Discord, with persistent storage, daily backups, and a systemd service that survives reboots.
Why this matters
OpenClaw runs fine on your laptop, but production needs 24/7 uptime, stable webhook endpoints, persistent memory, and secure remote access. Most setup guides skip server hardening, reverse proxy config, and backup planning.
Walkthrough
- 01
Choose your VPS and install Docker
OpenClaw needs a Linux server with Docker. Hetzner CX22 (2 vCPU, 4 GB RAM at $4/month) is the community favourite for price and performance.
- Provision an Ubuntu 22.04 or 24.04 VPS from Hetzner, DigitalOcean, or Hostinger (2 vCPU, 4 GB RAM minimum).
- SSH in and install Docker: curl -fsSL https://get.docker.com | sh
- Add your user to the docker group and log back in.
- 02
Pull and configure the OpenClaw container
Create the config directory and pull the official OpenClaw Docker image from GitHub Container Registry.
- Create directories: mkdir -p ~/openclaw/data
- Pull the image: docker pull ghcr.io/openclaw/openclaw:latest
- Create docker-compose.yml with port 18789 bound to localhost only.
- 03
Configure your AI provider and channels
Wire your API key and connect messaging channels before starting the gateway.
- Set ANTHROPIC_API_KEY or OPENAI_API_KEY in the container environment.
- Configure Telegram bot token or Discord bot token for channel access.
- Create a gateway auth token for secure remote access.
- 04
Run behind Nginx with automatic SSL
Keep the gateway bound to localhost and route public traffic through Nginx with Let's Encrypt or Caddy.
- Install Nginx and configure a reverse proxy pointing to 127.0.0.1:18789.
- Use Certbot or Caddy for automatic HTTPS certificate provisioning.
- Point your domain A record to the VPS IP before requesting the certificate.
- 05
Set up systemd and backups
Make the gateway auto-start on boot and back up the critical state directory.
- Create a systemd service file for the Docker Compose stack with Restart=always.
- Back up ~/openclaw/ daily: this contains all config, credentials, and session data.
- Test a restore before treating the server as production.
Where RepoAssistant fits
OpenClaw deployment takes 20 minutes if you know Linux. RepoAssistant does it for you: VPS, Docker, SSL, channels, and handover: fixed price.