Skip to content

Run OpenClaw 24/7 on GCP with Docker

I spent way too much time restarting my local dev environment every time my laptop went to sleep or the Wi-Fi flickered. If you want your agents to be useful, they need to stay awake. I found that running OpenClaw on a GCP Compute Engine instance is the best way to get 24/7 uptime for about $5 to $12 a month. It is quiet, cheap, and stays out of the way.

In this guide, I will show you how to set up a persistent Gateway on Google Cloud. We will use Docker to keep things clean and SSH tunnels to keep things secure.

  • A Google Cloud account (the free tier works, but I suggest a paid instance for better speed).
  • The gcloud CLI installed on your machine.
  • Basic knowledge of Docker and the command line.
  • Your API keys for models or messaging providers.

If you have done this before, here is the 5-minute path to getting live:

  1. Create the VM: Spin up an e2-small instance running Debian 12.
  2. Install Docker: Run the official install script and add your user to the docker group.
  3. Clone & Config: Pull the OpenClaw repo and set up your .env and docker-compose.yml.
  4. Build & Run: Build the custom image with your binaries and start the container.

First, you need a place for your VM to live. Open your terminal and run these commands to create a project and enable the right APIs.

Terminal window
# Create the project
gcloud projects create my-openclaw-project --name="OpenClaw Gateway"
gcloud config set project my-openclaw-project
# Enable the Compute API
gcloud services enable compute.googleapis.com

Make sure you enable billing in the Cloud Console or the VM will not start.

I recommend the e2-small machine type. The e2-micro is often free, but it tends to run out of memory when you start running complex tasks.

Terminal window
gcloud compute instances create openclaw-gateway \
--zone=us-central1-a \
--machine-type=e2-small \
--boot-disk-size=20GB \
--image-family=debian-12 \
--image-project=debian-cloud

SSH into your new VM. Note that it might take a minute for the VM to accept connections after it is first created.

Terminal window
gcloud compute ssh openclaw-gateway --zone=us-central1-a

Once you are in, run this to get Docker ready:

Terminal window
sudo apt-get update
sudo apt-get install -y git curl ca-certificates
curl -fsSL https://get.docker.com | sudo sh
sudo usermod -aG docker $USER
exit

Log back in so the group changes take effect.

Now we pull the code and set up our environment. I like to keep the configuration files on the host machine so they don’t disappear when the container updates.

Terminal window
git clone https://github.com/openclaw/openclaw.git
cd openclaw
mkdir -p ~/.openclaw/workspace

Create a .env file in the openclaw folder. Use openssl rand -hex 32 to create a strong token for your OPENCLAW_GATEWAY_TOKEN.

Terminal window
OPENCLAW_IMAGE=openclaw:latest
OPENCLAW_GATEWAY_TOKEN=your-secure-token
OPENCLAW_GATEWAY_BIND=lan
OPENCLAW_GATEWAY_PORT=18789
OPENCLAW_CONFIG_DIR=/home/$USER/.openclaw
OPENCLAW_WORKSPACE_DIR=/home/$USER/.openclaw/workspace
GOG_KEYRING_PASSWORD=your-keyring-pass
XDG_CONFIG_HOME=/home/node/.openclaw

You cannot just install tools like wacli or gog while the container is running because they will vanish on restart. You have to bake them into the image. Update your Dockerfile with the tools you need.

FROM node:22-bookworm
RUN apt-get update && apt-get install -y socat && rm -rf /var/lib/apt/lists/*
# Install your required binaries
RUN curl -L https://github.com/steipete/gog/releases/latest/download/gog_Linux_x86_64.tar.gz | tar -xz -C /usr/local/bin
RUN curl -L https://github.com/steipete/wacli/releases/latest/download/wacli_Linux_x86_64.tar.gz | tar -xz -C /usr/local/bin
RUN curl -L https://github.com/steipete/goplaces/releases/latest/download/goplaces_Linux_x86_64.tar.gz | tar -xz -C /usr/local/bin
RUN apt-get install -y ffmpeg
WORKDIR /app
COPY . .
RUN corepack enable && pnpm install && pnpm build && pnpm ui:install && pnpm ui:build
CMD ["node","dist/index.js"]

Launch the gateway:

Terminal window
docker compose build
docker compose up -d

The safest way to use the Control UI is through an SSH tunnel. This keeps the port closed to the public internet. Run this on your local laptop:

Terminal window
gcloud compute ssh openclaw-gateway --zone=us-central1-a -- -L 18789:127.0.0.1:18789

Now open http://127.0.0.1:18789/ in your browser and enter your token.

Connection Refused If you just created the VM, wait two minutes. Google needs a moment to set up your SSH keys.

Out of Memory (OOM) Errors If the logs show “Killed” or memory errors, you need a bigger VM. Stop the instance, change the machine type to e2-medium, and start it again.

Binaries are missing If which gog returns nothing inside the container, you forgot to rebuild. Run docker compose build --no-cache to make sure your Dockerfile changes are applied.

Permission Denied Make sure your host folders (~/.openclaw) have the right permissions so the Docker user can write to them.

Still stuck? Use the AI Setup Assistant for real-time help.

OpenClaw

OpenClaw Expert

Still stuck?

If this page didn't answer your case, ask OpenClaw Expert for step-by-step guidance.