OpenClaw
Deploy OpenClaw, an open source AI agent platform that runs locally and executes tasks through a persistent gateway service connecting communication channels, tools, and AI models.
You can configure and manage the system using a CLI onboarding wizard and a local web dashboard. This app allows you to connect to the OpenClaw dashboard via a secure HTTPS endpoint protected by HTPASSWD and creates a limited user on the system named openclaw.
1. Deploy OpenClaw
Follow the deployment instructions from the Get started section to configure the app, deploy it, and verify software installation.
For information on the app-specific configurations, see the Configuration options section.
Base distribution and plan
- Supported distribution: Ubuntu 24.04 LTS
- Recommended plans: All plan types and sizes can be used.
Configuration options
Configure the required options to deploy your instance. For additional customization, add advanced options.
The table maps the Cloud Manager UI fields to their corresponding API/CLI keys (stackscript_data) required for automated deployments.
StackScript ID: 2049320
| UI field | API/CLI key | Description |
|---|---|---|
| Required options | ||
| Limited sudo user | user_name | Your preferred username for the limited sudo user, entered without any capital letters, spaces, or special characters. When adding a limited sudo user, the user is created with a strong generated password for your new Linode instance, and the account is assigned to the sudo group, which provides elevated permissions when running commands with the sudo prefix.Note: For easier and more secure access with the sudo user, add an account SSH key for the Cloud Manager user during deployment and select that user as an |
| Email address (for the Let's Encrypt SSL certificate) | soa_email_address | The email address you want to use for generating the SSL certificates via Let’s Encrypt. |
| Advanced options | ||
| Disable root access over SSH | disable_root | Applies to a limited sudo user. To block the root user from logging in over SSH, select Yes. Defaults to No. Note: When you disable the root user from logging in over SSH and don't provide a valid Account SSH Key assigned to the |
| Linode API token | token_password | Applies to a custom domain. The Linode API token if you want to use Linode's DNS Manager to manage DNS records for your custom domain. Follow Manage personal access tokens to get your token on your account with Read/Write access to Domains.
|
| Subdomain | subdomain | Applies to a custom domain. The subdomain you want to use, like blog for blog.example.com. Use it only if you specify a Domain. |
| Domain | domain | Applies to a custom domain. The domain name you want to use, like example.com. Use it only if you specify a Linode API token. |
| Optional data exporter Add-ons | add_ons | An option to include add-ons for your deployment. Possible values are:
|
Notes:
- After the app deployment completes, the password for your limited sudo user is generated and stored in the
.credentialsfile in the home directory, along with application-specific passwords. Log in to your instance asrootthrough the Lish console or SSH, then runcat /home/$USERNAME/.credentialsto view its contents.- You can automatically configure a custom domain (optional) during deployment. To do that:
- First, configure your domain to use Linode’s name servers via your registrar. See Configure your domain's authoritative name servers for details.
- Once you complete that, specify the Linode API token, subdomain, and domain for the app in Cloud Manager or via API/CLI/Terraform.
Use API, CLI, or Terraform
In addition to deploying the app to a new Linode instance via Cloud Manager, you can also use the Linode API, CLI, or Terraform. When running the operation, you need to provide the StackScript ID, supported Linux distribution, and app-specific fields along with the standard Linode deployment configurations.
Note: Generate a personal access token to authenticate your API, CLI, or Terraform requests.
curl --location 'https://api.linode.com/v4/linode/instances' \
--header 'Content-Type: application/json' \
--header 'Accept: application/json' \
--header 'Authorization: Bearer abc123def456hij789klm' \
--data-raw '{
"region": "us-east",
"type": "g6-standard-2",
"image": "linode/ubuntu24.04",
"label": "my-openclaw-one-click-app",
"root_pass": "@C0mpl3x#P@ssw0rd",
"stackscript_id": 2049320,
"stackscript_data": {
"user_name":"jsmith",
"soa_email_address":"jsmith@example.com"
}
}'linode-cli linodes create \
--region us-east \
--type g6-standard-2 \
--label my-openclaw-one-click-app \
--image linode/ubuntu24.04 \
--root_pass @C0mpl3x#P@ssw0rd \
--stackscript_id 2049320 \
--stackscript_data '{"user_name":"jsmith", "soa_email_address":"jsmith@example.com"}'resource "linode_instance" "my-linode" {
region = "us-east"
type = "g6-standard-2"
label = "my-openclaw-one-click-app"
image = "linode/ubuntu24.04"
root_pass = "@C0mpl3x#P@ssw0rd"
stackscript_id = 2049320
stackscript_data = {
"user_name" = "jsmith"
"soa_email_address" = "jsmith@example.com"
}
}2. Access OpenClaw
Onboard OpenClaw
Once the deployment is complete, openclaw is installed on the instance but is not running yet. Before you can start using OpenClaw, you need to go through the onboarding wizard. This app triggers onboarding for you when you log in as root.
-
Log in to your instance.
If you disabled root login to the server during the setup of the OpenClaw app, log in as a sudo user.
ssh admin@YOUR_INSTANCE_IPReplace
YOUR_INSTANCE_IPwith the IP address of your Linode instance andadminwith the sudo user you created. -
Escalate privileges to root. Once you’ve logged in, the motd (message of the day) appears.
********************************************************* Akamai Connected Cloud OpenClaw Quick Deploy App Dashboard URL: https://172-235-150-14.ip.linodeusercontent.com Credentials File: /home/admin/.credentials Documentation: https://techdocs.akamai.com/quick-deploy-apps/docs/openclaw ********************************************************* -
Copy the sudo password from the
~/.credentialsfile and enter thesudo su -command in the terminal. -
When prompted for the password, paste the sudo password you copied from the
~/.credentialsfile. When you log in asroot, the onboarding wizard message appears. -
If you're ready to perform the onboarding, enter
y. It takes you to OpenClaw’s onboarding wizard where you can complete the configuration.Once the setup is complete, the onboarding script is removed.
Confirm the gateway status
At this point, you’ve configured OpenClaw on the server. To verify the gateway is running, you need to become the openclaw user.
- Run the
su - openclawcommand in the terminal as therootuser. - To view the gateway status, run the
openclaw gateway statuscommand as theopenclawuser. The output should display the running state, along with other gateway details.
Access the dashboard
Once onboarding is complete and the gateway is running, you can access the dashboard using one of these methods:
- Access the dashboard from the domain you’ve configured in the initial app deployment.
- If you didn't configure your domain, assess the dashboard using your instance’s rDNS value. For example,
172-233-177-79.ip.linodeusercontent.com. You can view the rDNS value from the Linode’s Network tab.
To authenticate to the dashboard, you need to provide two authentication methods:
- Dashboard token: If you didn’t get a dashboard token during the onboarding steps, follow these steps:
- Become the
openclawuser by runningsu - openclaw. - Run the
openclaw dashboard --no-opencommand. - Get the entire token value, for example,
#token=a12bc34def56ghi7j, from theDashboard URLfield.
- Become the
- Nginx basic auth: Get the
Htpasswdusername and password from the.credentialsfile. - Once you're set, you can access the dashboard. For example, using
https://172-233-177-79.ip.linodeusercontent.com/#token=a12bc34def56ghi7j. - When you access the web page, you're prompted for the HTPASSWD details, including the
openclawusername and password from the.credentialsfile.
Additional resources
For more information about the installed packages, see their official documentation.
Note that we can't vouch for the accuracy or timeliness of externally hosted resources.
Updated about 11 hours ago
