Dear Readers,
so I wanted to self-host OpenClaw — an open-source platform for personal AI agents. Own assistants on Telegram, managing my Obsidian vault, running 24/7 on cheap ARM hardware. This is the first post in a series documenting the setup, gotchas and all.
The Server#
I went with a Hetzner CAX11 — their cheapest ARM64 (Ampere Altra) box running Ubuntu 24.04 Noble. ARM64 is fantastic bang for your buck. But as I quickly found out, not everything in the Node.js world is happy about running on ARM.
The domain clawd.it points to the server via a Cloudflare A record. Simple enough.
Node.js 22: The ARM64 Trap#
OpenClaw needs Node.js 22+. Naturally, I reached for NodeSource first:
curl -fsSL https://deb.nodesource.com/setup_22.x | bash -
apt-get install -y nodejsOn this ARM64 box it stubbornly installed Node v18 regardless. The NodeSource repo just didn’t have v22 packages for arm64 at the time.
The fix — grab the official binary directly:
curl -sL https://nodejs.org/dist/v22.14.0/node-v22.14.0-linux-arm64.tar.xz \
| tar xJ -C /usr/local --strip-components=1Verify:
node --version # v22.14.0
npm --version # 10.9.2No package manager weirdness.
Installing OpenClaw#
With Node 22 in place, OpenClaw installs with two commands:
npm install -g openclaw@latest
openclaw onboardThe onboarding wizard asks you about:
- Provider: Anthropic (I’m using Claude via OAuth — more on that in a later post)
- Auth mode: Token-based gateway authentication
- Gateway port: 18789, bound to LAN
- Daemon: Systemd user service at
~/.config/systemd/user/openclaw-gateway.service
After that, the gateway runs as a systemd service. Standard stuff:
systemctl --user status openclaw-gateway
systemctl --user restart openclaw-gateway
journalctl --user -u openclaw-gateway -fEnvironment Variables#
The systemd service needs a couple of env vars:
OPENCLAW_GATEWAY_TOKEN— what clients use to auth with the gatewayGITHUB_TOKEN— optional, for agents that need GitHub access
Drop them in via the service override:
systemctl --user edit openclaw-gateway[Service]
Environment="OPENCLAW_GATEWAY_TOKEN=your-token-here"
Environment="GITHUB_TOKEN=ghp_..."Reload and restart:
systemctl --user daemon-reload
systemctl --user restart openclaw-gatewayFirst Signs of Life#
At this point the OpenClaw gateway is up on port 18789. Quick sanity check:
curl http://localhost:18789/healthBut it’s only reachable from the server itself. In the next post we’ll put Nginx Proxy Manager in front of it for HTTPS, basic auth, and WebSocket support.
