↓ Skip to main content
← All research

Setting Up OpenClaw on a Hetzner ARM64 Server

2 min read Patrik Grobshäuser Archive

Research summary

Getting Node.js 22 and OpenClaw running on a fresh Hetzner CAX ARM64 Ubuntu Noble server — including the ARM64 gotchas nobody warns you about.

Installation - This article is part of a series.
Part 1: This Article

Dear Readers,

so I wanted to self-host OpenClaw — an open-source platform for personal AI agents. Own assistants on Telegram, managing my Obsidian vault, running 24/7 on cheap ARM hardware. This is the first post in a series documenting the setup, gotchas and all.

The Server
#

I went with a Hetzner CAX11 — their cheapest ARM64 (Ampere Altra) box running Ubuntu 24.04 Noble. ARM64 is fantastic bang for your buck. But as I quickly found out, not everything in the Node.js world is happy about running on ARM.

The domain clawd.it points to the server via a Cloudflare A record. Simple enough.

Node.js 22: The ARM64 Trap
#

OpenClaw needs Node.js 22+. Naturally, I reached for NodeSource first:

curl -fsSL https://deb.nodesource.com/setup_22.x | bash -
apt-get install -y nodejs

On this ARM64 box it stubbornly installed Node v18 regardless. The NodeSource repo just didn’t have v22 packages for arm64 at the time.

The fix — grab the official binary directly:

curl -sL https://nodejs.org/dist/v22.14.0/node-v22.14.0-linux-arm64.tar.xz \
  | tar xJ -C /usr/local --strip-components=1

Verify:

node --version  # v22.14.0
npm --version   # 10.9.2

No package manager weirdness.

Installing OpenClaw
#

With Node 22 in place, OpenClaw installs with two commands:

npm install -g openclaw@latest
openclaw onboard

The onboarding wizard asks you about:

  • Provider: Anthropic (I’m using Claude via OAuth — more on that in a later post)
  • Auth mode: Token-based gateway authentication
  • Gateway port: 18789, bound to LAN
  • Daemon: Systemd user service at ~/.config/systemd/user/openclaw-gateway.service

After that, the gateway runs as a systemd service. Standard stuff:

systemctl --user status openclaw-gateway
systemctl --user restart openclaw-gateway
journalctl --user -u openclaw-gateway -f

Environment Variables
#

The systemd service needs a couple of env vars:

  • OPENCLAW_GATEWAY_TOKEN — what clients use to auth with the gateway
  • GITHUB_TOKEN — optional, for agents that need GitHub access

Drop them in via the service override:

systemctl --user edit openclaw-gateway
[Service]
Environment="OPENCLAW_GATEWAY_TOKEN=your-token-here"
Environment="GITHUB_TOKEN=ghp_..."

Reload and restart:

systemctl --user daemon-reload
systemctl --user restart openclaw-gateway

First Signs of Life
#

At this point the OpenClaw gateway is up on port 18789. Quick sanity check:

curl http://localhost:18789/health

But it’s only reachable from the server itself. In the next post we’ll put Nginx Proxy Manager in front of it for HTTPS, basic auth, and WebSocket support.


Next up: Securing the Dashboard with Nginx Proxy Manager