openclaw-vps-setup

Provision and harden a Hetzner VPS for OpenClaw behind Tailscale VPN.

22|1|Updated Jan 14, 2026
One-click install
npx skills add https://github.com/AlexAtmtit/custom-skills --skill openclaw-vps-setup
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: openclaw-vps-setup
Source: https://github.com/AlexAtmtit/custom-skills/tree/main/openclaw-vps-setup
Command: npx skills add https://github.com/AlexAtmtit/custom-skills --skill openclaw-vps-setup

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve?

This guide turns Claude into a patient, step-by-step setup assistant that securely deploys OpenClaw on a Hetzner VPS with production-grade hardening, including Tailscale VPN, non-root operation, loopback-only gateway, seamless Telegram integration, and a rigorous security verification workflow.

Core Features & Use Cases

  • End-to-end VPS provisioning and hardening for a secure OpenClaw deployment.
  • Non-root operation + loopback gateway with SSH and firewall controls to minimize exposure.
  • Tailscale-based access ensuring private, VPN-only connectivity between your devices and the VPS.
  • Telegram bot integration for command and control from Telegram with privacy-conscious, local Whisper processing.
  • Security verification & governance with a mandated checklist to validate network, access, and gateway safety before going live.

Quick Start

Follow the guided phases to provision, harden, install, and verify OpenClaw on Hetzner with Tailscale and Telegram integration.

Frequently Asked Questions about openclaw-vps-setup

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I securely deploy OpenClaw on a Hetzner VPS?

To securely deploy OpenClaw on a Hetzner VPS, provision a Debian 12/13 server, create a non-root user, harden SSH, configure a firewall, and restrict the gateway to loopback-only access behind a Tailscale VPN.

Does OpenClaw VPS hardening require a Tailscale VPN?

Yes, Tailscale VPN is required for OpenClaw VPS hardening to ensure private, VPN-only connectivity between your devices and the server, minimizing network exposure and restricting public access to the gateway.

How do I set up Telegram bot integration with OpenClaw on a VPS?

Set up Telegram bot integration with OpenClaw by providing a Telegram bot token during configuration, enabling command and control from Telegram alongside privacy-conscious, local Whisper processing on the VPS.

What are the prerequisites for hardening a Hetzner VPS for OpenClaw?

Prerequisites for hardening a Hetzner VPS for OpenClaw include a Debian 12/13 server, an active Tailscale account, a configured non-root user, SSH access, and a valid Telegram bot token for integration.

Why should I restrict the OpenClaw gateway to loopback-only on a VPS?

Restricting the OpenClaw gateway to loopback-only on a VPS minimizes public network exposure, ensuring the service remains inaccessible from the public internet and only reachable through the secure Tailscale VPN tunnel.

How do I verify the security of my OpenClaw VPS deployment?

Verify the security of your OpenClaw VPS deployment by following the mandated end-to-end security verification workflow, which validates network configurations, access controls, and gateway safety before going live.