Oracle Cloud
OpenClaw on Oracle Cloud (Always Free ARM)
Goal
Run a persistent OpenClaw Gateway on Oracle Cloud's Always Free ARM tier.
Oracle's free tier can be a great fit for OpenClaw (especially if you already have an OCI account), but it comes with tradeoffs:
- ARM architecture (most things work, but some binaries may be x86-only)
- Capacity and signup can be finicky
Cost Comparison (2026)
| Provider | Plan | Specs | Price/mo | Notes |
| | - | -- |
Prerequisites
- Oracle Cloud account (''signup'') β see ''community signup guide'' if you hit issues
- Tailscale account (free at ''tailscale.com'')
- ~30 minutes
1) Create an OCI Instance
1. Log into ''Oracle Cloud Console''
2. Navigate to Compute β Instances β Create Instance
3. Configure:
- ''Name:'' ''openclaw''
- Image: Ubuntu 24.04 (aarch64)
- ''Shape:'' ''VM.Standard.A1.Flex'' (Ampere ARM)
- OCPUs: 2 (or up to 4)
- Memory: 12 GB (or up to 24 GB)
- Boot volume: 50 GB (up to 200 GB free)
- SSH key: Add your public key
4. Click Create
5. Note the public IP address
Tip: If instance creation fails with "Out of capacity", try a different availability domain or retry later. Free tier capacity is limited.
2) Connect and Update
ssh ubuntu@YOUR_PUBLIC_IP sudo apt update && sudo apt upgrade -y sudo apt install -y build-essential
''Note:'' ''build-essential'' is required for ARM compilation of some dependencies.
3) Configure User and Hostname
sudo hostnamectl set-hostname openclaw sudo passwd ubuntu sudo loginctl enable-linger ubuntu
4) Install Tailscale
curl -fsSL https://tailscale.com/install.sh | sh sudo tailscale up --ssh --hostname=openclaw
This enables Tailscale SSH, so you can connect via ''ssh openclaw'' from any device on your tailnet β no public IP needed.
Verify:
tailscale status
''From now on, connect via Tailscale:'' ''ssh ubuntu@openclaw'' (or use the Tailscale IP).
5) Install OpenClaw
curl -fsSL https://openclaw.ai/install.sh | bash source ~/.bashrc
When prompted "How do you want to hatch your bot?", select "Do this later".
Tutorial.alert.info
6) Configure Gateway (loopback + token auth) and enable Tailscale Serve
Use token auth as the default. It's predictable and avoids needing any "insecure auth" Control UI flags.
openclaw config set gateway.bind loopback openclaw config set gateway.auth.mode token openclaw doctor --generate-gateway-token openclaw config set gateway.tailscale.mode serve openclaw config set gateway.trustedProxies '["127.0.0.1"]' systemctl --user restart openclaw-gateway
7) Verify
openclaw --version systemctl --user status openclaw-gateway tailscale serve status curl http://localhost:18789
8) Lock Down VCN Security
Now that everything is working, lock down the VCN to block all traffic except Tailscale. OCI's Virtual Cloud Network acts as a firewall at the network edge β traffic is blocked before it reaches your instance.
1. Go to Networking β Virtual Cloud Networks in the OCI Console
2. Click your VCN β Security Lists β Default Security List
3. Remove all ingress rules except:
- ''0.0.0.0/0 UDP 41641'' (Tailscale)
4. Keep default egress rules (allow all outbound)
This blocks SSH on port 22, HTTP, HTTPS, and everything else at the network edge. From now on, you can only connect via Tailscale.
Security: VCN + Tailscale (recommended baseline)
With the VCN locked down (only UDP 41641 open) and Gateway bound to loopback, you get strong defense-in-depth: public traffic is blocked at the network edge, and admin access happens over your tailnet.
This setup often removes _need_ for extra host-based firewall rules purely to stop Internet-wide SSH brute force β but you should still keep the OS updated, run ''openclaw security audit'', and verify you aren't accidentally listening on public interfaces.
#
What's Already Protected
| Traditional Step | Needed? | Why |
| | - |
| UFW firewall | No | VCN blocks before traffic reaches instance |
| fail2ban | No | No brute force if port 22 blocked at VCN |
| sshd hardening | No | Tailscale SSH doesn't use sshd |
| Disable root login | No | Tailscale uses Tailscale identity, not system users |
| SSH key-only auth | No | Tailscale authenticates via your tailnet |
| IPv6 hardening | Usually not | Depends on your VCN/subnet settings; verify what's actually assigned/exposed |
#
Still Recommended
- ''Credential permissions:'' ''chmod 700 ~/.openclaw''
- ''Security audit:'' ''openclaw security audit''
- ''System updates:'' ''sudo apt update && sudo apt upgrade'' regularly
- ''Monitor Tailscale:'' Review devices in ''Tailscale admin console''
#
Verify Security Posture
sudo ss -tlnp | grep -v '127.0.0.1|::1' tailscale status | grep -q 'offers: ssh' && echo "Tailscale SSH active" sudo systemctl disable --now ssh
Troubleshooting
#
Instance creation fails ("Out of capacity")
Free tier ARM instances are popular. Try:
- Different availability domain
- Retry during off-peak hours (early morning)
- Use the "Always Free" filter when selecting shape
#
Tailscale won't connect
sudo tailscale status sudo tailscale up --ssh --hostname=openclaw --reset
#
Gateway won't start
openclaw gateway status openclaw doctor --non-interactive journalctl --user -u openclaw-gateway -n 50
#
Can't reach Control UI
tailscale serve status curl http://localhost:18789 systemctl --user restart openclaw-gateway
#
ARM binary issues
Some tools may not have ARM builds. Check:
uname -m # Should show aarch64
Most npm packages work fine. For binaries, look for ''linux-arm64'' or ''aarch64'' releases.
See Also
- ''Gateway remote access'' β other remote access patterns
- ''Tailscale integration'' β full Tailscale docs
- ''Gateway configuration'' β all config options
- ''DigitalOcean guide'' β if you want paid + easier signup
- ''Hetzner guide'' β Docker-based alternative