Why Docker for OpenClaw?
Running OpenClaw in Docker keeps your host clean, makes upgrades a single docker compose pull, and lets you move between machines by copying one volume. If you already run Docker on your server, this is the fastest path to production.
Minimal docker-compose.yml
Create a directory and add your compose file:
mkdir -p ~/openclaw && cd ~/openclawversion: "3.8"
services:
openclaw:
image: openclaw/openclaw:latest
ports:
- "18789:18789"
environment:
- OPENCLAW_GATEWAY_BIND=0.0.0.0
volumes:
- openclaw-data:/home/node/.openclaw
volumes:
openclaw-data:Start it:
docker compose up -d
docker compose logs -f openclawThe gateway starts on port 18789. Grab your token:
docker compose exec openclaw openclaw config get gateway.tokenConfigure allowedOrigins
The Control UI needs to know which origins are allowed. Replace YOUR_HOST_IP with your actual IP:
# Find your IP
hostname -I | awk '{print $1}'Add to your compose environment:
environment:
- OPENCLAW_GATEWAY_BIND=0.0.0.0
- OPENCLAW_GATEWAY_CONTROLUI_ALLOWEDORIGINS=["http://192.168.1.50:18789"]Common mistake: using localhost here only works if the browser runs on the same machine. Always use the real IP for remote access.
Master this topic with hands-on labs
Go beyond reading — build real projects in sandboxed environments with expert video guidance.
Browse Courses →Fix Volume Permissions
If you see EACCES: permission denied, the container runs as UID 1000:
# For named volumes — recreate
docker compose down
docker volume rm openclaw_openclaw-data
docker compose up -d
# For bind mounts — fix ownership
sudo chown -R 1000:1000 ./openclaw-data
sudo chmod 700 ./openclaw-dataAdd Tailscale Access
If you use Tailscale, add your Tailscale hostname to allowedOrigins:
environment:
- OPENCLAW_GATEWAY_BIND=0.0.0.0
- OPENCLAW_GATEWAY_CONTROLUI_ALLOWEDORIGINS=["http://192.168.1.50:18789","http://my-server.tail12345.ts.net:18789"]This lets you access the Control UI from any device on your tailnet.
Behind a Reverse Proxy
For HTTPS with Caddy or Nginx, remove the port mapping and let the proxy handle TLS:
services:
openclaw:
image: openclaw/openclaw:latest
environment:
- OPENCLAW_GATEWAY_BIND=0.0.0.0
- OPENCLAW_GATEWAY_CONTROLUI_ALLOWEDORIGINS=["https://openclaw.yourdomain.com"]
networks:
- proxy
networks:
proxy:
external: trueCaddy example:
openclaw.yourdomain.com {
reverse_proxy openclaw:18789
}Connect Messaging Channels
Once the gateway is running, connect your channels:
- Discord: Create a bot, add the token via
openclaw configure --section discord - Telegram: Talk to BotFather, get a token, configure via
openclaw configure --section telegram - Signal: Link your phone number through the Signal integration
Each channel runs independently — one OpenClaw instance handles all of them.
Get weekly IT automation tips
Docker, Ansible, Terraform, MLOps — curated insights delivered to your inbox. No spam.
Subscribe Free →Verify Everything Works
# Check gateway is responding
TOKEN=$(docker compose exec openclaw openclaw config get gateway.token)
curl -s -o /dev/null -w "%{http_code}" \
-H "x-api-key: $TOKEN" \
http://localhost:18789/v1/modelsExpected: 200. If you get 401, your token does not match. If connection refused, the gateway is not running.
Upgrades
docker compose pull
docker compose up -dYour data persists in the named volume. OpenClaw handles config migrations automatically.
What's Next?
With OpenClaw running in Docker, explore these next:
- Install custom skills to extend your agent
- Connect Discord for team automation
- Set up heartbeats for proactive monitoring
- Secure your agent for production use
---
Ready to go deeper? Check out our hands-on course: OpenClaw Agent — practical exercises you can follow along on your own machine.
Further reading
To go deeper, OpenClaw-driven CVE remediation with Ansible expands on these patterns in production.
Ready to learn by doing?
Stop reading tutorials — start building. Expert video courses with hands-on labs in real sandboxed environments.
Related Articles
OpenClaw Volume Permissions Fix
Fix OpenClaw Docker volume permission errors. Resolve EACCES issues for named volumes and bind mounts with troubleshooting steps.
Troubleshoot OpenClaw Gateway Errors
Fix OpenClaw gateway errors: 401 unauthorized, connection refused, origin not allowed, and WebSocket failures with resolution guides.
OpenClaw Gateway Bind Modes Guide
Learn OpenClaw gateway bind modes: loopback, lan, tailnet, auto, and custom. Pick the right mode for your network setup.
OpenClaw Heartbeats
Learn how to configure OpenClaw heartbeats for proactive monitoring — email checks, calendar alerts, weather updates, and more.
Understanding OpenClaw's Memory System
Learn how OpenClaw agents maintain memory across sessions using file-based persistence — daily notes, MEMORY.md, and workspace context.
OpenClaw Node Pairing
Pair your phone or IoT devices with OpenClaw for camera access, location tracking, screen recording, and remote commands.
Explore topics
Browse more articles on the topics covered here.