Running OpenClaw 24/7 on a Hetzner VPS with Docker
I often find that running AI tools on a local machine is great for testing, but it falls apart when I need things to stay online. Keeping a laptop open all night is not a real solution, and managing a home server can be a headache. I want a setup that stays alive 24/7 without me thinking about it.
If you want a reliable way to host your OpenClaw Gateway for the price of a coffee, a small Hetzner VPS is the way to go. I use this approach because it keeps the state durable and the costs low.
What You’ll Need
Section titled “What You’ll Need”- Hetzner VPS with root access (Ubuntu or Debian)
- SSH access from your laptop
- Docker and Docker Compose
- Model auth credentials
- Provider credentials (WhatsApp, Telegram, or Gmail)
Quick Start
Section titled “Quick Start”1. Prepare the Server
Section titled “1. Prepare the Server”Rent a small VPS and connect via SSH:
ssh root@YOUR_VPS_IPUpdate the system and install Docker using the official script:
apt-get updateapt-get install -y git curl ca-certificatescurl -fsSL https://get.docker.com | sh2. Set Up the Repository
Section titled “2. Set Up the Repository”Clone the code and create the directories where your data will live. I recommend these specific paths to keep things organized:
git clone https://github.com/openclaw/openclaw.gitcd openclaw
mkdir -p /root/.openclawmkdir -p /root/.openclaw/workspace
# Set ownership to the container userchown -R 1000:1000 /root/.openclawchown -R 1000:1000 /root/.openclaw/workspace3. Configure Environment and Compose
Section titled “3. Configure Environment and Compose”Create a .env file in the root directory. Use openssl rand -hex 32 to generate your secrets.
OPENCLAW_IMAGE=openclaw:latestOPENCLAW_GATEWAY_TOKEN=change-me-nowOPENCLAW_GATEWAY_BIND=lanOPENCLAW_GATEWAY_PORT=18789
OPENCLAW_CONFIG_DIR=/root/.openclawOPENCLAW_WORKSPACE_DIR=/root/.openclaw/workspace
GOG_KEYRING_PASSWORD=change-me-nowXDG_CONFIG_HOME=/home/node/.openclawNow, update your docker-compose.yml to use these variables and mount the volumes:
services: openclaw-gateway: image: ${OPENCLAW_IMAGE} build: . restart: unless-stopped env_file: - .env environment: - HOME=/home/node - NODE_ENV=production - TERM=xterm-256color - OPENCLAW_GATEWAY_BIND=${OPENCLAW_GATEWAY_BIND} - OPENCLAW_GATEWAY_PORT=${OPENCLAW_GATEWAY_PORT} - OPENCLAW_GATEWAY_TOKEN=${OPENCLAW_GATEWAY_TOKEN} - GOG_KEYRING_PASSWORD=${GOG_KEYRING_PASSWORD} - XDG_CONFIG_HOME=${XDG_CONFIG_HOME} - PATH=/home/linuxbrew/.linuxbrew/bin:/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin volumes: - ${OPENCLAW_CONFIG_DIR}:/home/node/.openclaw - ${OPENCLAW_WORKSPACE_DIR}:/home/node/.openclaw/workspace ports: - "127.0.0.1:${OPENCLAW_GATEWAY_PORT}:18789" command: [ "node", "dist/index.js", "gateway", "--bind", "${OPENCLAW_GATEWAY_BIND}", "--port", "${OPENCLAW_GATEWAY_PORT}", ]4. Bake Binaries and Launch
Section titled “4. Bake Binaries and Launch”Installing tools inside a running container is a mistake because they vanish when the container restarts. You must add them to your Dockerfile.
Update your Dockerfile to include the tools you need:
FROM node:22-bookworm
RUN apt-get update && apt-get install -y socat && rm -rf /var/lib/apt/lists/*
# Gmail CLIRUN curl -L https://github.com/steipete/gog/releases/latest/download/gog_Linux_x86_64.tar.gz \ | tar -xz -C /usr/local/bin && chmod +x /usr/local/bin/gog
# Google Places CLIRUN curl -L https://github.com/steipete/goplaces/releases/latest/download/goplaces_Linux_x86_64.tar.gz \ | tar -xz -C /usr/local/bin && chmod +x /usr/local/bin/goplaces
# WhatsApp CLIRUN curl -L https://github.com/steipete/wacli/releases/latest/download/wacli_Linux_x86_64.tar.gz \ | tar -xz -C /usr/local/bin && chmod +x /usr/local/bin/wacli
WORKDIR /appCOPY package.json pnpm-lock.yaml pnpm-workspace.yaml .npmrc ./COPY ui/package.json ./ui/package.jsonCOPY scripts ./scripts
RUN corepack enableRUN pnpm install --frozen-lockfile
COPY . .RUN pnpm buildRUN pnpm ui:installRUN pnpm ui:build
ENV NODE_ENV=production
CMD ["node","dist/index.js"]Build and start the gateway:
docker compose builddocker compose up -d openclaw-gateway5. Access the UI
Section titled “5. Access the UI”Since the port is bound to 127.0.0.1 for safety, use an SSH tunnel from your laptop to see the UI:
ssh -N -L 18789:127.0.0.1:18789 root@YOUR_VPS_IPNavigate to http://127.0.0.1:18789/ and enter your gateway token.
Troubleshooting
Section titled “Troubleshooting”- Binaries missing on restart: If you find that tools like
wacliorgogare gone after a reboot, it means you installed them at runtime. You must add them to theDockerfileand rebuild the image. - Connection Refused: If you cannot reach the UI, ensure your SSH tunnel is active. If you choose to expose the port publicly, check your firewall settings and the
OPENCLAW_GATEWAY_BINDvariable.
If you run into other issues, the AI Setup Assistant can help you debug.
What’s Next
Section titled “What’s Next”OpenClaw Expert
Still stuck?
If this page didn't answer your case, ask OpenClaw Expert for step-by-step guidance.