Deploying OpenClaw Gateway on Fly.io
I spent way too much time trying to keep my gateway running on a spare laptop under my desk. Between the random restarts and the nightmare of setting up stable port forwarding for Discord webhooks, it was a mess. I switched to Fly.io because it handles the infra, gives me a public URL with HTTPS automatically, and keeps my data safe on a persistent volume. If you want your gateway to just stay online without babysitting a server, this is the way to do it.
What You’ll Need
Section titled “What You’ll Need”Before we start, make sure you have these four things ready:
- flyctl CLI installed and logged in.
- A Fly.io account (the free tier is great, but you’ll need a credit card on file).
- Your model API keys (like Anthropic or OpenAI).
- Your channel tokens (Discord bot token or Telegram bot token).
Quick Start: The 5-Minute Path
Section titled “Quick Start: The 5-Minute Path”This is the fastest way to get your gateway live. We’ll create the app, set up a disk for your data, and push the code.
1. Create the App and Volume
Section titled “1. Create the App and Volume”Open your terminal and run these commands:
# Clone the repogit clone https://github.com/openclaw/openclaw.gitcd openclaw
# Create the app (choose a unique name)fly apps create my-openclaw
# Create a 1GB volume for your database and config# I recommend 'iad' (Virginia) or 'lhr' (London)fly volumes create openclaw_data --size 1 --region iad2. Configure fly.toml
Section titled “2. Configure fly.toml”Create or edit your fly.toml file. I recommend using at least 2GB of RAM. OpenClaw can be hungry when it’s processing lots of messages, and 512MB will likely cause crashes.
app = "my-openclaw"primary_region = "iad"
[build] dockerfile = "Dockerfile"
[env] NODE_ENV = "production" OPENCLAW_PREFER_PNPM = "1" OPENCLAW_STATE_DIR = "/data" NODE_OPTIONS = "--max-old-space-size=1536"
[processes] app = "node dist/index.js gateway --allow-unconfigured --port 3000 --bind lan"
[http_service] internal_port = 3000 force_https = true auto_stop_machines = false auto_start_machines = true min_machines_running = 1 processes = ["app"]
[[vm]] size = "shared-cpu-2x" memory = "2048mb"
[mounts] source = "openclaw_data" destination = "/data"3. Set Your Secrets
Section titled “3. Set Your Secrets”Don’t put your API keys in the config file. Use Fly secrets instead. It’s safer and prevents you from accidentally leaking them in logs.
# Generate a random token for your Gatewayfly secrets set OPENCLAW_GATEWAY_TOKEN=$(openssl rand -hex 32)
# Add your provider keysfly secrets set ANTHROPIC_API_KEY=sk-ant-...fly secrets set DISCORD_BOT_TOKEN=MTQ...4. Deploy and Initialize
Section titled “4. Deploy and Initialize”Now, push it to the cloud:
fly deployOnce it’s up, you need to create your openclaw.json config file inside the persistent volume. Use SSH to jump into the machine:
fly ssh consoleInside the console, run this to create your basic config:
mkdir -p /datacat > /data/openclaw.json << 'EOF'{ "agents": { "defaults": { "model": { "primary": "anthropic/claude-3-5-sonnet-latest" } }, "list": [{ "id": "main", "default": true }] }, "channels": { "discord": { "enabled": true } }}EOFexitRestart the machine to pick up the new config: fly machine restart --all.
Troubleshooting
Section titled “Troubleshooting”If things aren’t working, check these common issues:
- Health Checks Failing: This usually happens if your
internal_portinfly.tomldoesn’t match the--portin your start command. Make sure both are set to3000. - Out of Memory (OOM): If you see
SIGABRTor the app keeps restarting, 512MB isn’t enough. Update your machine to 2GB usingfly machine update <id> --vm-memory 2048. - “Already Running” Error: If the gateway crashed, it might leave a lock file. Run
fly ssh console -C "rm -f /data/gateway.*.lock"then restart. - Connection Refused: Ensure you have
--bind lanin your start command. Without it, the gateway only listens to itself, and Fly’s proxy can’t find it.
Private Deployment (Hardened)
Section titled “Private Deployment (Hardened)”If you don’t need a public URL and want to hide your gateway from internet scanners, you can run a private setup.
- Remove the
[http_service]block from yourfly.toml. - Deploy with
fly deploy. - Access the UI by running
fly proxy 3000:3000on your local machine and visitinglocalhost:3000.
This keeps your gateway off the public internet while still letting you use it for outbound tasks like Discord bots or Telegram.
If you get stuck or need a custom configuration, check out the AI Setup Assistant.
What’s Next
Section titled “What’s Next”OpenClaw Expert
Still stuck?
If this page didn't answer your case, ask OpenClaw Expert for step-by-step guidance.