Plans you can read before they run
clawops plan emits a JSON artifact you review, diff and commit. clawops apply executes exactly that. Nothing reaches your cloud account straight from a natural-language instruction.
clawops migrate to bring an existing 1.x deployment across.Migrating from 1.xProvision and operate self-hosted OpenClaw on AWS, GCP, Azure or any Linux box, with plans you read before they run.
npm install -g @clawops/cliRunning an agent on your own hardware means owning a VM, a firewall, a container, secrets and an upgrade path. clawops owns that layer so you can treat the gateway as a deployment target rather than a pet.
clawops plan emits a JSON artifact you review, diff and commit. clawops apply executes exactly that. Nothing reaches your cloud account straight from a natural-language instruction.
clawops installs the Pulumi CLI it needs on first use, or uses a compatible one already on your PATH. Your state lives in your own bucket, and clawops offers to create it.
Security groups and firewalls start closed. SSH and gateway ports open only to CIDRs your plan names explicitly, never 0.0.0.0/0.
clawops reads your existing CLI profiles: AWS_PROFILE, gcloud ADC, Azure env. It stores no cloud credentials of its own, anywhere.
Every operation is a typed tool with explicit safety annotations, so a coding agent knows what is read-only, what is destructive, and what needs confirmation.
logs, ssh, tunnel, monitor, backup, migrate, harden: the things you need on day two, not just the first deploy.
The local path needs a Linux box you can SSH into, with no cloud account required to try it. The full quickstart covers cloud providers and day-two operations.
doctor verifies Node, SSH keys, known_hosts and cloud credentials before anything is provisioned.
npm install -g @clawops/cli clawops doctor
Any reachable Ubuntu, Debian or RHEL box. Docker is installed for you.
clawops init --provider local --host 10.0.0.42
Pin a version rather than a moving tag. clawops refuses latest and stable: a tag that moves changes what is deployed without changing the plan.
clawops up --openclaw-version 2026.9.2
Forward the port over SSH rather than exposing it to the internet.
clawops tunnel # Control UI on http://127.0.0.1:18789
| Provider | Compute | Plan / apply | Secret store | Hardening |
|---|---|---|---|---|
| AWS | EC2 | yes | Secrets Manager, SSM | yes |
| GCP | Compute Engine | yes | Secret Manager | yes |
| Azure | Linux VM | yes | Key Vault | yes |
| Local / any VM | SSH | use up | env, file | yes |
Worth knowing before you install it, rather than after.
No clustering, load balancing or failover. For high availability, run multiple stacks and route between them yourself.
The gateway is reached over an SSH tunnel or a reverse proxy you bring. Certificate and DNS automation is planned, not shipped.
clawops provisions and operates the infrastructure OpenClaw runs on. Authoring agents, skills and prompts is OpenClaw’s job.
clawops will not tell you what a stack costs before you create it. Check your provider’s calculator for the instance type you choose.
OpenClaw 2026.8.1 changed the container runtime contract: state moved into SQLite, config moved to a writable path, and model providers, then channels, became install-gated plugins. clawops mounts the state directory, validates config against OpenClaw’s own schema before writing it, and installs the plugins your config names during apply.
clawops migrate takes a verified backup, extracts the state from the running container, and starts 2.0 against it. Device identity is preserved, so paired devices do not need re-pairing. Your old config is not applied, since on 1.x it was read by nothing, so a valid 2.0 config is written and the old one reported for review.
The 1.x line is maintained under the legacy dist-tag until 2027-03-31 for OpenClaw 2026.7.1-2 and earlier: npm install -g @clawops/cli@legacy.