OpenClawSkills
GitHub
Platforms β€’ TutorialHeader.readTime

Oracle Cloud

OpenClaw on Oracle Cloud (Always Free ARM)

Tutorial.step

Goal

Run a persistent OpenClaw Gateway on Oracle Cloud's Always Free ARM tier.

Oracle's free tier can be a great fit for OpenClaw (especially if you already have an OCI account), but it comes with tradeoffs:

- ARM architecture (most things work, but some binaries may be x86-only)

- Capacity and signup can be finicky

Tutorial.step

Cost Comparison (2026)

| Provider | Plan | Specs | Price/mo | Notes |

| | - | -- |

Tutorial.step

Prerequisites

- Oracle Cloud account (''signup'') β€” see ''community signup guide'' if you hit issues

- Tailscale account (free at ''tailscale.com'')

- ~30 minutes

Tutorial.step

1) Create an OCI Instance

1. Log into ''Oracle Cloud Console''

2. Navigate to Compute β†’ Instances β†’ Create Instance

3. Configure:

- ''Name:'' ''openclaw''

- Image: Ubuntu 24.04 (aarch64)

- ''Shape:'' ''VM.Standard.A1.Flex'' (Ampere ARM)

- OCPUs: 2 (or up to 4)

- Memory: 12 GB (or up to 24 GB)

- Boot volume: 50 GB (up to 200 GB free)

- SSH key: Add your public key

4. Click Create

5. Note the public IP address

Tip: If instance creation fails with "Out of capacity", try a different availability domain or retry later. Free tier capacity is limited.

Tutorial.step

2) Connect and Update

Bash
ssh ubuntu@YOUR_PUBLIC_IP


sudo apt update && sudo apt upgrade -y
sudo apt install -y build-essential

''Note:'' ''build-essential'' is required for ARM compilation of some dependencies.

Tutorial.step

3) Configure User and Hostname

Bash
sudo hostnamectl set-hostname openclaw


sudo passwd ubuntu


sudo loginctl enable-linger ubuntu
Tutorial.step

4) Install Tailscale

Bash
curl -fsSL https://tailscale.com/install.sh | sh
sudo tailscale up --ssh --hostname=openclaw

This enables Tailscale SSH, so you can connect via ''ssh openclaw'' from any device on your tailnet β€” no public IP needed.

Verify:

Bash
tailscale status

''From now on, connect via Tailscale:'' ''ssh ubuntu@openclaw'' (or use the Tailscale IP).

Tutorial.step

5) Install OpenClaw

Bash
curl -fsSL https://openclaw.ai/install.sh | bash
source ~/.bashrc

When prompted "How do you want to hatch your bot?", select "Do this later".

Tutorial.alert.info

Note: Note: If you hit ARM-native build issues, start with system packages (e.g. <code className="bg-white/10 px-1.5 py-0.5 rounded text-emerald-300 text-sm">sudo apt install -y build-essential</code>) before reaching for Homebrew.
Tutorial.step

6) Configure Gateway (loopback + token auth) and enable Tailscale Serve

Use token auth as the default. It's predictable and avoids needing any "insecure auth" Control UI flags.

Bash
openclaw config set gateway.bind loopback


openclaw config set gateway.auth.mode token
openclaw doctor --generate-gateway-token


openclaw config set gateway.tailscale.mode serve
openclaw config set gateway.trustedProxies '["127.0.0.1"]'

systemctl --user restart openclaw-gateway
Tutorial.step

7) Verify

Bash
openclaw --version


systemctl --user status openclaw-gateway


tailscale serve status


curl http://localhost:18789
Tutorial.step

8) Lock Down VCN Security

Now that everything is working, lock down the VCN to block all traffic except Tailscale. OCI's Virtual Cloud Network acts as a firewall at the network edge β€” traffic is blocked before it reaches your instance.

1. Go to Networking β†’ Virtual Cloud Networks in the OCI Console

2. Click your VCN β†’ Security Lists β†’ Default Security List

3. Remove all ingress rules except:

- ''0.0.0.0/0 UDP 41641'' (Tailscale)

4. Keep default egress rules (allow all outbound)

This blocks SSH on port 22, HTTP, HTTPS, and everything else at the network edge. From now on, you can only connect via Tailscale.

Tutorial.step

Security: VCN + Tailscale (recommended baseline)

With the VCN locked down (only UDP 41641 open) and Gateway bound to loopback, you get strong defense-in-depth: public traffic is blocked at the network edge, and admin access happens over your tailnet.

This setup often removes _need_ for extra host-based firewall rules purely to stop Internet-wide SSH brute force β€” but you should still keep the OS updated, run ''openclaw security audit'', and verify you aren't accidentally listening on public interfaces.

#

Tutorial.step

What's Already Protected

| Traditional Step | Needed? | Why |

| | - |

| UFW firewall | No | VCN blocks before traffic reaches instance |

| fail2ban | No | No brute force if port 22 blocked at VCN |

| sshd hardening | No | Tailscale SSH doesn't use sshd |

| Disable root login | No | Tailscale uses Tailscale identity, not system users |

| SSH key-only auth | No | Tailscale authenticates via your tailnet |

| IPv6 hardening | Usually not | Depends on your VCN/subnet settings; verify what's actually assigned/exposed |

#

Tutorial.step

Still Recommended

- ''Credential permissions:'' ''chmod 700 ~/.openclaw''

- ''Security audit:'' ''openclaw security audit''

- ''System updates:'' ''sudo apt update && sudo apt upgrade'' regularly

- ''Monitor Tailscale:'' Review devices in ''Tailscale admin console''

#

Tutorial.step

Verify Security Posture

Bash
sudo ss -tlnp | grep -v '127.0.0.1|::1'


tailscale status | grep -q 'offers: ssh' && echo "Tailscale SSH active"


sudo systemctl disable --now ssh
Tutorial.step

Troubleshooting

#

Tutorial.step

Instance creation fails ("Out of capacity")

Free tier ARM instances are popular. Try:

- Different availability domain

- Retry during off-peak hours (early morning)

- Use the "Always Free" filter when selecting shape

#

Tutorial.step

Tailscale won't connect

Bash
sudo tailscale status


sudo tailscale up --ssh --hostname=openclaw --reset

#

Tutorial.step

Gateway won't start

Bash
openclaw gateway status
openclaw doctor --non-interactive
journalctl --user -u openclaw-gateway -n 50

#

Tutorial.step

Can't reach Control UI

Bash
tailscale serve status


curl http://localhost:18789


systemctl --user restart openclaw-gateway

#

Tutorial.step

ARM binary issues

Some tools may not have ARM builds. Check:

Bash
uname -m  # Should show aarch64

Most npm packages work fine. For binaries, look for ''linux-arm64'' or ''aarch64'' releases.

Tutorial.step

See Also

- ''Gateway remote access'' β€” other remote access patterns

- ''Tailscale integration'' β€” full Tailscale docs

- ''Gateway configuration'' β€” all config options

- ''DigitalOcean guide'' β€” if you want paid + easier signup

- ''Hetzner guide'' β€” Docker-based alternative