Skip to content

Running OpenClaw 24/7 on a Hetzner VPS with Docker

I often find that running AI tools on a local machine is great for testing, but it falls apart when I need things to stay online. Keeping a laptop open all night is not a real solution, and managing a home server can be a headache. I want a setup that stays alive 24/7 without me thinking about it.

If you want a reliable way to host your OpenClaw Gateway for the price of a coffee, a small Hetzner VPS is the way to go. I use this approach because it keeps the state durable and the costs low.

  • Hetzner VPS with root access (Ubuntu or Debian)
  • SSH access from your laptop
  • Docker and Docker Compose
  • Model auth credentials
  • Provider credentials (WhatsApp, Telegram, or Gmail)

Rent a small VPS and connect via SSH:

Terminal window
ssh root@YOUR_VPS_IP

Update the system and install Docker using the official script:

Terminal window
apt-get update
apt-get install -y git curl ca-certificates
curl -fsSL https://get.docker.com | sh

Clone the code and create the directories where your data will live. I recommend these specific paths to keep things organized:

Terminal window
git clone https://github.com/openclaw/openclaw.git
cd openclaw
mkdir -p /root/.openclaw
mkdir -p /root/.openclaw/workspace
# Set ownership to the container user
chown -R 1000:1000 /root/.openclaw
chown -R 1000:1000 /root/.openclaw/workspace

Create a .env file in the root directory. Use openssl rand -hex 32 to generate your secrets.

Terminal window
OPENCLAW_IMAGE=openclaw:latest
OPENCLAW_GATEWAY_TOKEN=change-me-now
OPENCLAW_GATEWAY_BIND=lan
OPENCLAW_GATEWAY_PORT=18789
OPENCLAW_CONFIG_DIR=/root/.openclaw
OPENCLAW_WORKSPACE_DIR=/root/.openclaw/workspace
GOG_KEYRING_PASSWORD=change-me-now
XDG_CONFIG_HOME=/home/node/.openclaw

Now, update your docker-compose.yml to use these variables and mount the volumes:

services:
openclaw-gateway:
image: ${OPENCLAW_IMAGE}
build: .
restart: unless-stopped
env_file:
- .env
environment:
- HOME=/home/node
- NODE_ENV=production
- TERM=xterm-256color
- OPENCLAW_GATEWAY_BIND=${OPENCLAW_GATEWAY_BIND}
- OPENCLAW_GATEWAY_PORT=${OPENCLAW_GATEWAY_PORT}
- OPENCLAW_GATEWAY_TOKEN=${OPENCLAW_GATEWAY_TOKEN}
- GOG_KEYRING_PASSWORD=${GOG_KEYRING_PASSWORD}
- XDG_CONFIG_HOME=${XDG_CONFIG_HOME}
- PATH=/home/linuxbrew/.linuxbrew/bin:/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin
volumes:
- ${OPENCLAW_CONFIG_DIR}:/home/node/.openclaw
- ${OPENCLAW_WORKSPACE_DIR}:/home/node/.openclaw/workspace
ports:
- "127.0.0.1:${OPENCLAW_GATEWAY_PORT}:18789"
command:
[
"node",
"dist/index.js",
"gateway",
"--bind",
"${OPENCLAW_GATEWAY_BIND}",
"--port",
"${OPENCLAW_GATEWAY_PORT}",
]

Installing tools inside a running container is a mistake because they vanish when the container restarts. You must add them to your Dockerfile.

Update your Dockerfile to include the tools you need:

FROM node:22-bookworm
RUN apt-get update && apt-get install -y socat && rm -rf /var/lib/apt/lists/*
# Gmail CLI
RUN curl -L https://github.com/steipete/gog/releases/latest/download/gog_Linux_x86_64.tar.gz \
| tar -xz -C /usr/local/bin && chmod +x /usr/local/bin/gog
# Google Places CLI
RUN curl -L https://github.com/steipete/goplaces/releases/latest/download/goplaces_Linux_x86_64.tar.gz \
| tar -xz -C /usr/local/bin && chmod +x /usr/local/bin/goplaces
# WhatsApp CLI
RUN curl -L https://github.com/steipete/wacli/releases/latest/download/wacli_Linux_x86_64.tar.gz \
| tar -xz -C /usr/local/bin && chmod +x /usr/local/bin/wacli
WORKDIR /app
COPY package.json pnpm-lock.yaml pnpm-workspace.yaml .npmrc ./
COPY ui/package.json ./ui/package.json
COPY scripts ./scripts
RUN corepack enable
RUN pnpm install --frozen-lockfile
COPY . .
RUN pnpm build
RUN pnpm ui:install
RUN pnpm ui:build
ENV NODE_ENV=production
CMD ["node","dist/index.js"]

Build and start the gateway:

Terminal window
docker compose build
docker compose up -d openclaw-gateway

Since the port is bound to 127.0.0.1 for safety, use an SSH tunnel from your laptop to see the UI:

Terminal window
ssh -N -L 18789:127.0.0.1:18789 root@YOUR_VPS_IP

Navigate to http://127.0.0.1:18789/ and enter your gateway token.

  • Binaries missing on restart: If you find that tools like wacli or gog are gone after a reboot, it means you installed them at runtime. You must add them to the Dockerfile and rebuild the image.
  • Connection Refused: If you cannot reach the UI, ensure your SSH tunnel is active. If you choose to expose the port publicly, check your firewall settings and the OPENCLAW_GATEWAY_BIND variable.

If you run into other issues, the AI Setup Assistant can help you debug.

OpenClaw

OpenClaw Expert

Still stuck?

If this page didn't answer your case, ask OpenClaw Expert for step-by-step guidance.