The Error
Error: EACCES: permission denied, open '/home/node/.openclaw/openclaw.json'OpenClaw's Docker container runs as user node (UID 1000, GID 1000). If the mounted volume is owned by root or another user, the process cannot read or write its config files.
Named Volumes (Recommended)
Docker named volumes usually get correct permissions automatically. If they do not:
# Remove and recreate
docker compose down
docker volume rm openclaw_openclaw-data
docker compose up -dDocker creates the volume with the correct ownership on first run.
Bind Mounts
Bind mounts inherit host filesystem permissions. Fix them:
# Create the directory
mkdir -p ./openclaw-data
# Set ownership to UID 1000
sudo chown -R 1000:1000 ./openclaw-data
sudo chmod 700 ./openclaw-dataYour docker-compose.yml:
services:
openclaw:
image: openclaw/openclaw:latest
volumes:
- ./openclaw-data:/home/node/.openclawMaster this topic with hands-on labs
Go beyond reading — build real projects in sandboxed environments with expert video guidance.
Browse Courses →Verify Permissions
# Check host directory
ls -la ./openclaw-data/
# Check inside container
docker compose exec openclaw ls -la /home/node/.openclaw/Both should show node (or UID 1000) as owner.
SELinux Systems (RHEL, Fedora)
On SELinux-enabled hosts, add the :z flag:
volumes:
- ./openclaw-data:/home/node/.openclaw:zThe :z flag tells Docker to relabel the volume for the container's SELinux context. Without it, SELinux blocks access even if Unix permissions are correct.
If you use a shared volume across multiple containers, use :Z (uppercase) instead.
Rootless Docker
Rootless Docker maps UIDs differently. Check the actual UID mapping:
# Find the mapped UID
cat /proc/$(docker inspect --format '{{.State.Pid}}' openclaw-openclaw-1)/uid_mapFor rootless Docker, you may need to adjust ownership to match the mapped UID.
Get weekly IT automation tips
Docker, Ansible, Terraform, MLOps — curated insights delivered to your inbox. No spam.
Subscribe Free →Common Mistakes
- Running
chownwithoutsudo: you need root to change ownership to UID 1000 if your user is not 1000 - Forgetting to recreate after
chown: the container caches the mount — restart withdocker compose restart - Using
:ro(read-only) mount: OpenClaw needs write access to update config, memory, and workspace files
Prevention
Use named volumes in production. They handle permissions automatically and survive docker compose down:
volumes:
openclaw-data:
driver: localOnly use bind mounts when you need direct host access to the files (debugging, backups).
Related Posts
- Deploy OpenClaw with Docker Compose for the full Docker setup
- Troubleshoot OpenClaw Gateway Errors for other common issues
- SELinux File Contexts and Labels for SELinux deep dive
---
Ready to go deeper? Check out our hands-on course: OpenClaw Agent — practical exercises you can follow along on your own machine.
Related guide
Related reading: agentic Ansible automation with OpenClaw covers this in real-world detail.
Ready to learn by doing?
Stop reading tutorials — start building. Expert video courses with hands-on labs in real sandboxed environments.
Related Articles
Deploy OpenClaw with Docker Compose
Step-by-step guide to deploy OpenClaw using Docker Compose. Cover networking, volumes, reverse proxy, and Tailscale setups.
Troubleshoot OpenClaw Gateway Errors
Fix OpenClaw gateway errors: 401 unauthorized, connection refused, origin not allowed, and WebSocket failures with resolution guides.
OpenClaw Reverse Proxy with Caddy
Set up HTTPS for OpenClaw using Caddy reverse proxy. Automatic TLS certificates, WebSocket support, and production config.
OpenClaw vs ChatGPT
Compare OpenClaw's self-hosted approach with ChatGPT and other cloud AI services. Learn the trade-offs between control, privacy, and convenience.
OpenClaw vs LangChain vs AutoGPT
Compare OpenClaw with LangChain, AutoGPT, and other AI agent frameworks. Understand the differences in architecture, use cases, and philosophy.
openSUSE Tumbleweed: Safe Rolling
openSUSE Tumbleweed combines rolling-release freshness with automated testing. The safest way to run bleeding-edge Linux in 2026.
Explore topics
Browse more articles on the topics covered here.