| Agent + local LLM (small) | 8 GB | 4 cores | 80 GB |
| Production with skills | 4 GB | 2 cores | 60 GB |
---
Server Setup
Step 1: Initial Server Configuration
# Connect to your VPS
ssh root@your-server-ip
# Update system
apt update && apt upgrade -y
# Create a dedicated user
adduser openclaw
usermod -aG sudo openclaw
# Switch to the new user
su - openclaw
Step 2: Install Node.js
# Install Node.js 20 LTS
curl -fsSL https://deb.nodesource.com/setup_20.x | sudo -E bash -
sudo apt-get install -y nodejs
# Verify
node --version # v20.x.x
npm --version # 10.x.x
Step 3: Install OpenClaw
# Install globally
sudo npm install -g @openclaw/cli
# Initialize configuration
openclaw init
# Verify
openclaw doctor
---
Process Management with systemd
Create a systemd Service
sudo tee /etc/systemd/system/openclaw.service > /dev/null << 'EOF'
[Unit]
Description=OpenClaw AI Agent
After=network.target
[Service]
Type=simple
User=openclaw
Group=openclaw
WorkingDirectory=/home/openclaw
ExecStart=/usr/bin/openclaw start --headless
Restart=always
RestartSec=10
Environment=NODE_ENV=production
# Security hardening
NoNewPrivileges=yes
PrivateTmp=yes
ProtectSystem=strict
ReadWritePaths=/home/openclaw
[Install]
WantedBy=multi-user.target
EOF
Enable and Start
# Reload systemd
sudo systemctl daemon-reload
# Enable on boot
sudo systemctl enable openclaw
# Start the service
sudo systemctl start openclaw
# Check status
sudo systemctl status openclaw
Useful Commands
# View logs
sudo journalctl -u openclaw -f
# Restart after config changes
sudo systemctl restart openclaw
# Stop the agent
sudo systemctl stop openclaw
---
Security Hardening
SSH Security
# Disable root login and password auth
sudo tee -a /etc/ssh/sshd_config << 'EOF'
PermitRootLogin no
PasswordAuthentication no
PubkeyAuthentication yes
EOF
sudo systemctl restart sshd
Firewall Setup
# Install and configure UFW
sudo apt install -y ufw
# Allow SSH
sudo ufw allow 22/tcp
# Allow OpenClaw webhook port (if using webhooks)
sudo ufw allow 8080/tcp
# Enable firewall
sudo ufw enable
sudo ufw status
Fail2ban
sudo apt install -y fail2ban
sudo systemctl enable fail2ban
sudo systemctl start fail2ban
---
Reverse Proxy with Nginx
If your agent uses webhooks, set up Nginx with SSL:
# Install Nginx and Certbot
sudo apt install -y nginx certbot python3-certbot-nginx
# Configure Nginx
sudo tee /etc/nginx/sites-available/openclaw << 'EOF'
server {
server_name agent.yourdomain.com;
location / {
proxy_pass http://127.0.0.1:8080;
proxy_http_version 1.1;
proxy_set_header Upgrade $http_upgrade;
proxy_set_header Connection "upgrade";
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
}
}
EOF
# Enable site
sudo ln -s /etc/nginx/sites-available/openclaw /etc/nginx/sites-enabled/
sudo nginx -t
sudo systemctl reload nginx
# Get SSL certificate
sudo certbot --nginx -d agent.yourdomain.com
---
Monitoring
Health Check Script
#!/bin/bash
# /home/openclaw/healthcheck.sh
if ! systemctl is-active --quiet openclaw; then
echo "OpenClaw is down! Restarting..."
sudo systemctl restart openclaw
# Optional: Send notification
curl -s -X POST "https://api.telegram.org/bot$BOT_TOKEN/sendMessage" \
-d "chat_id=$CHAT_ID&text=⚠️ OpenClaw was restarted on $(hostname)"
fi
# Add to crontab (every 5 minutes)
crontab -e
# Add: */5 * * * * /home/openclaw/healthcheck.sh
---
Troubleshooting
| Problem | Solution |
| Service won't start | Check journalctl -u openclaw -n 50 |
| High memory usage | Set NODE_OPTIONS=--max-old-space-size=512 |
| Webhook not receiving | Check firewall (ufw status) and Nginx logs |