Skip to content

Running OpenClaw on Oracle Cloud Always Free ARM

I have spent way too much time looking for the perfect “forever free” server. Most free tiers are either too small to run anything useful or they expire after a few weeks. It is frustrating to set up a project only to have the trial end right when you get things working.

Oracle Cloud’s Always Free ARM tier is one of the few places where you actually get enough power to run a persistent gateway without a monthly bill. It can be a bit finicky to sign up for, and ARM architecture has its own quirks, but it is a great fit for hosting OpenClaw. Here is how I set it up.

Log into your Oracle Cloud Console and go to Compute → Instances → Create Instance.

Use these settings:

  • Name: openclaw
  • Image: Ubuntu 24.04 (aarch64)
  • Shape: VM.Standard.A1.Flex (Ampere ARM)
  • OCPUs: 2 (up to 4)
  • Memory: 12 GB (up to 24 GB)
  • Boot volume: 50 GB
  • SSH key: Add your public key

If you see an “Out of capacity” error, try a different availability domain or wait a bit. Free tier capacity is limited. Once it’s ready, grab the public IP.

I recommend installing build-essential right away because some ARM dependencies need it for compilation.

Terminal window
# Connect via public IP
ssh ubuntu@YOUR_PUBLIC_IP
# Update system
sudo apt update && sudo apt upgrade -y
sudo apt install -y build-essential

I like to keep things organized by setting a proper hostname and enabling lingering so services keep running after I log out.

Terminal window
# Set hostname
sudo hostnamectl set-hostname openclaw
# Set password for ubuntu user
sudo passwd ubuntu
# Enable lingering
sudo loginctl enable-linger ubuntu

Tailscale makes networking much easier. I use it so I don’t have to leave port 22 open to the whole internet.

Terminal window
curl -fsSL https://tailscale.com/install.sh | sh
sudo tailscale up --ssh --hostname=openclaw

From here on, you can connect using ssh ubuntu@openclaw from any device on your tailnet.

Run the install script. When it asks “How do you want to hatch your bot?”, select “Do this later”.

Terminal window
curl -fsSL https://openclaw.ai/install.sh | bash
source ~/.bashrc

I recommend using token authentication. It is predictable and keeps the Control UI secure. I also use Tailscale Serve to handle HTTPS and access control.

Terminal window
# Keep the Gateway private on the VM
openclaw config set gateway.bind loopback
# Require auth for the Gateway + Control UI
openclaw config set gateway.auth.mode token
openclaw doctor --generate-gateway-token
# Expose over Tailscale Serve (HTTPS + tailnet access)
openclaw config set gateway.tailscale.mode serve
openclaw config set gateway.trustedProxies '["127.0.0.1"]'
systemctl --user restart openclaw-gateway

Check that everything is running as expected:

Terminal window
# Check version and daemon
openclaw --version
systemctl --user status openclaw-gateway
# Check Tailscale Serve
tailscale serve status
# Test local response
curl http://localhost:18789

Now that you have Tailscale working, you should lock down the OCI firewall (VCN). This blocks traffic before it even hits your server.

  1. Go to Networking → Virtual Cloud Networks in the OCI Console.
  2. Click your VCN → Security Lists → Default Security List.
  3. Remove all ingress rules except: 0.0.0.0/0 UDP 41641 (this is for Tailscale).

This blocks standard SSH and HTTP/HTTPS from the public internet. You will only be able to reach the machine through your tailnet.

You can now reach your Control UI from any device on your Tailscale network at: https://openclaw.<tailnet-name>.ts.net/

You don’t need an SSH tunnel because Tailscale handles the HTTPS encryption and authentication for you.

Instance creation fails (“Out of capacity”)

Section titled “Instance creation fails (“Out of capacity”)”

ARM instances are very popular on the free tier. I suggest trying a different availability domain or retrying during off-peak hours (like early morning).

If things get stuck, check the status or reset the connection:

Terminal window
sudo tailscale status
sudo tailscale up --ssh --hostname=openclaw --reset

Use these commands to see what is going wrong:

Terminal window
openclaw gateway status
openclaw doctor --non-interactive
journalctl --user -u openclaw-gateway -n 50

If you run into issues with tools not working, check your architecture with uname -m. It should show aarch64. Most things work fine, but always look for linux-arm64 releases when downloading binaries manually.

If you have more questions or run into a specific error, check out the AI Setup Assistant.

OpenClaw

OpenClaw Expert

Still stuck?

If this page didn't answer your case, ask OpenClaw Expert for step-by-step guidance.