Running OpenClaw on Oracle Cloud Always Free ARM
I have spent way too much time looking for the perfect “forever free” server. Most free tiers are either too small to run anything useful or they expire after a few weeks. It is frustrating to set up a project only to have the trial end right when you get things working.
Oracle Cloud’s Always Free ARM tier is one of the few places where you actually get enough power to run a persistent gateway without a monthly bill. It can be a bit finicky to sign up for, and ARM architecture has its own quirks, but it is a great fit for hosting OpenClaw. Here is how I set it up.
What You’ll Need
Section titled “What You’ll Need”- Oracle Cloud account (signup)
- Tailscale account (free at tailscale.com)
- ~30 minutes
Quick Start
Section titled “Quick Start”1. Create an OCI Instance
Section titled “1. Create an OCI Instance”Log into your Oracle Cloud Console and go to Compute → Instances → Create Instance.
Use these settings:
- Name:
openclaw - Image: Ubuntu 24.04 (aarch64)
- Shape:
VM.Standard.A1.Flex(Ampere ARM) - OCPUs: 2 (up to 4)
- Memory: 12 GB (up to 24 GB)
- Boot volume: 50 GB
- SSH key: Add your public key
If you see an “Out of capacity” error, try a different availability domain or wait a bit. Free tier capacity is limited. Once it’s ready, grab the public IP.
2. Connect and Update
Section titled “2. Connect and Update”I recommend installing build-essential right away because some ARM dependencies need it for compilation.
# Connect via public IPssh ubuntu@YOUR_PUBLIC_IP
# Update systemsudo apt update && sudo apt upgrade -ysudo apt install -y build-essential3. Configure User and Hostname
Section titled “3. Configure User and Hostname”I like to keep things organized by setting a proper hostname and enabling lingering so services keep running after I log out.
# Set hostnamesudo hostnamectl set-hostname openclaw
# Set password for ubuntu usersudo passwd ubuntu
# Enable lingeringsudo loginctl enable-linger ubuntu4. Install Tailscale
Section titled “4. Install Tailscale”Tailscale makes networking much easier. I use it so I don’t have to leave port 22 open to the whole internet.
curl -fsSL https://tailscale.com/install.sh | shsudo tailscale up --ssh --hostname=openclawFrom here on, you can connect using ssh ubuntu@openclaw from any device on your tailnet.
5. Install OpenClaw
Section titled “5. Install OpenClaw”Run the install script. When it asks “How do you want to hatch your bot?”, select “Do this later”.
curl -fsSL https://openclaw.ai/install.sh | bashsource ~/.bashrc6. Configure Gateway and Tailscale Serve
Section titled “6. Configure Gateway and Tailscale Serve”I recommend using token authentication. It is predictable and keeps the Control UI secure. I also use Tailscale Serve to handle HTTPS and access control.
# Keep the Gateway private on the VMopenclaw config set gateway.bind loopback
# Require auth for the Gateway + Control UIopenclaw config set gateway.auth.mode tokenopenclaw doctor --generate-gateway-token
# Expose over Tailscale Serve (HTTPS + tailnet access)openclaw config set gateway.tailscale.mode serveopenclaw config set gateway.trustedProxies '["127.0.0.1"]'
systemctl --user restart openclaw-gateway7. Verify the Setup
Section titled “7. Verify the Setup”Check that everything is running as expected:
# Check version and daemonopenclaw --versionsystemctl --user status openclaw-gateway
# Check Tailscale Servetailscale serve status
# Test local responsecurl http://localhost:187898. Lock Down VCN Security
Section titled “8. Lock Down VCN Security”Now that you have Tailscale working, you should lock down the OCI firewall (VCN). This blocks traffic before it even hits your server.
- Go to Networking → Virtual Cloud Networks in the OCI Console.
- Click your VCN → Security Lists → Default Security List.
- Remove all ingress rules except:
0.0.0.0/0 UDP 41641(this is for Tailscale).
This blocks standard SSH and HTTP/HTTPS from the public internet. You will only be able to reach the machine through your tailnet.
Accessing the Control UI
Section titled “Accessing the Control UI”You can now reach your Control UI from any device on your Tailscale network at:
https://openclaw.<tailnet-name>.ts.net/
You don’t need an SSH tunnel because Tailscale handles the HTTPS encryption and authentication for you.
Troubleshooting
Section titled “Troubleshooting”Instance creation fails (“Out of capacity”)
Section titled “Instance creation fails (“Out of capacity”)”ARM instances are very popular on the free tier. I suggest trying a different availability domain or retrying during off-peak hours (like early morning).
Tailscale won’t connect
Section titled “Tailscale won’t connect”If things get stuck, check the status or reset the connection:
sudo tailscale statussudo tailscale up --ssh --hostname=openclaw --resetGateway won’t start
Section titled “Gateway won’t start”Use these commands to see what is going wrong:
openclaw gateway statusopenclaw doctor --non-interactivejournalctl --user -u openclaw-gateway -n 50ARM binary issues
Section titled “ARM binary issues”If you run into issues with tools not working, check your architecture with uname -m. It should show aarch64. Most things work fine, but always look for linux-arm64 releases when downloading binaries manually.
If you have more questions or run into a specific error, check out the AI Setup Assistant.
What’s Next
Section titled “What’s Next”- Gateway remote access — Other ways to connect remotely.
- Tailscale integration — Full Tailscale documentation.
- Gateway configuration — See all available config options.
- DigitalOcean guide — If you prefer a paid option with an easier signup.
OpenClaw Expert
Still stuck?
If this page didn't answer your case, ask OpenClaw Expert for step-by-step guidance.