Skip to main content
🎤 Luca Berton is speaking at Red Hat Summit & KubeCon EU 2026!Learn more →
Back to Blog

OpenClaw + Tailscale Remote Access

Access OpenClaw securely from anywhere using Tailscale. Zero port forwarding, zero firewall rules, encrypted connections.

Luca BertonApril 6, 20262 min read

The Problem

You run OpenClaw on a home server or VPS. You want to reach it from your laptop, phone, or another machine — without exposing port 18789 to the internet.

Tailscale solves this. It creates an encrypted mesh network between your devices. No port forwarding, no dynamic DNS, no firewall holes.

Install Tailscale

On the machine running OpenClaw:

bash
curl -fsSL https://tailscale.com/install.sh | sh
sudo tailscale up

Note your Tailscale IP:

bash
tailscale ip -4
# Example: 100.64.0.5

Configure OpenClaw

Set the bind mode to tailnet:

bash
openclaw config set gateway.bind tailnet
openclaw config set gateway.controlui.allowedOrigins '["http://100.64.0.5:18789"]'
openclaw gateway restart

Or use the Tailscale hostname:

bash
openclaw config set gateway.controlui.allowedOrigins '["http://my-server.tail12345.ts.net:18789"]'
openclaw gateway restart
Related Course

Master this topic with hands-on labs

Go beyond reading — build real projects in sandboxed environments with expert video guidance.

Browse Courses →

Access from Any Device

From any device on your tailnet, open:

http://my-server.tail12345.ts.net:18789

Enter your gateway token when prompted. Works from your phone, laptop, or any other Tailscale-connected device.

Docker + Tailscale

If OpenClaw runs in Docker, Tailscale runs on the host. Bind to 0.0.0.0 and let Tailscale handle access control:

yaml
services:
  openclaw:
    image: openclaw/openclaw:latest
    ports:
      - "18789:18789"
    environment:
      - OPENCLAW_GATEWAY_BIND=0.0.0.0
      - OPENCLAW_GATEWAY_CONTROLUI_ALLOWEDORIGINS=["http://100.64.0.5:18789"]
    volumes:
      - openclaw-data:/home/node/.openclaw

Then use Tailscale ACLs to restrict which devices can reach port 18789.

Tailscale ACLs

Lock down access in your Tailscale admin console:

json
{
  "acls": [
    {
      "action": "accept",
      "src": ["tag:admin"],
      "dst": ["tag:openclaw:18789"]
    }
  ]
}

Only devices tagged admin can reach your OpenClaw instance.

Stay Updated

Get weekly IT automation tips

Docker, Ansible, Terraform, MLOps — curated insights delivered to your inbox. No spam.

Subscribe Free →

HTTPS with Tailscale

Tailscale can provision HTTPS certificates for your tailnet hostnames:

bash
tailscale cert my-server.tail12345.ts.net

Then point Caddy at the certs or use tailscale serve:

bash
tailscale serve --bg https+insecure://localhost:18789

Now you have HTTPS at https://my-server.tail12345.ts.net with zero configuration.

Why Not Just Use a VPN?

Traditional VPNs route all traffic through a single gateway. Tailscale creates direct connections between devices. Your OpenClaw traffic goes directly from your phone to your server — no hub bottleneck.

---

Ready to go deeper? Check out our hands-on course: OpenClaw Agent — practical exercises you can follow along on your own machine.

For a production-focused walkthrough, see Luca Berton's guide on OpenClaw-driven CVE remediation with Ansible.

Ready to learn by doing?

Stop reading tutorials — start building. Expert video courses with hands-on labs in real sandboxed environments.

Share this article
LB
Luca Berton

Docker Captain, IT automation expert, Red Hat Summit & KubeCon speaker. Building hands-on education for DevOps engineers at CopyPasteLearn.

Related Articles

Explore topics

Browse more articles on the topics covered here.