Why run OpenClaw in Docker
- Servers and VPS hosting
- Keeping OpenClaw separate from your system
- One-command updates and easy rollbacks
- Moving your setup between machines
- People who already use Docker
- Beginners on a personal laptop (use the native installer)
- iMessage, which needs macOS directly
- Machines with little RAM if you build images yourself
Docker requirements for OpenClaw
- Docker
- Docker Engine (Linux) or Docker Desktop (Mac, Windows)
- Compose
- Docker Compose v2 (the
docker composecommand) - Memory
- At least 6 GB RAM to build the image yourself. Smaller machines can use pre-built images.
- Other
git, plus an AI model API key
Official OpenClaw Docker images
ghcr.io/openclaw/openclaw:latestThe primary registry, used by OpenClaw's release automation. Start here.
ghcr.io/openclaw/openclaw:latest-browserBundles Chromium so the browser tool works in the container. The standard image doesn't include it.
openclaw/openclaw:latestDocker Hub mirror of the same image, if GHCR is blocked on your network.
Avoid unofficial mirrors and look-alike image names. Copies using the old Clawdbot and Moltbot names have been used to spread malware.
Build your setup command
Pick your options and copy the result into step 3.
Install Docker and Compose
On Debian or Ubuntu, the official OpenClaw server guides use Docker's convenience script:
sudo apt-get update
sudo apt-get install -y git curl ca-certificates
curl -fsSL https://get.docker.com | shInstall Docker Desktop from docker.com, open it once so the engine starts, and give it at least 6 GB of memory in its settings if you'll build images.
Check both are ready:
docker --version
docker compose versionGet the OpenClaw setup files
The Compose file and setup script live in the official repository.
git clone https://github.com/openclaw/openclaw.git
cd openclawRun the setup script
Choose a pre-built image and run the script. Or paste the command from the builder above.
export OPENCLAW_IMAGE="ghcr.io/openclaw/openclaw:latest"
./scripts/docker/setup.shWhat the script does
- Pulls or builds the gateway image you chose
- Syncs
.env, fixes file permissions and runs onboarding - Asks for your AI provider API keys
- Generates a gateway token and writes it to
.env - Starts the gateway with Docker Compose
Without OPENCLAW_IMAGE, the script builds the image locally. That's the step that needs 6 GB of RAM.
Open the Control UI
Get the dashboard link, then open it in your browser:
docker compose run --rm openclaw-cli dashboard --no-openThe Control UI runs at http://127.0.0.1:18789/. Your gateway token is saved in the .env file in the openclaw folder. On a remote server, connect through an SSH tunnel first. See the VPS guide.
Connect a chat app
Run OpenClaw commands through the openclaw-cli container. For example, add a Telegram bot:
docker compose run --rm openclaw-cli channels add --channel telegram --token "<bot-token>"For channels that log in with a QR code or account, such as WhatsApp:
docker compose run --rm openclaw-cli channels loginMessage your bot, then approve yourself the same way you would outside Docker, prefixed with docker compose run --rm openclaw-cli. Next: build your first workflow.
How the OpenClaw containers fit together
The always-running service: chat channels, agents, memory, tools and the Control UI on port 18789.
A short-lived container for commands such as pairing, channels and the dashboard link. It's removed after each run with --rm.
OPENCLAW_CONFIG_DIR on your host, mounted at /home/node/.openclaw. Holds settings, memory and tokens.
OPENCLAW_WORKSPACE_DIR on your host, mounted at /home/node/workspace. The agent's working files.
Because your data lives in host folders, you can delete and recreate the containers without losing anything. Back up those two folders, not the containers.
OpenClaw Docker command cheat sheet
| Task | Command |
|---|---|
| Follow logs | docker compose logs -f openclaw-gateway |
| Restart | docker compose restart openclaw-gateway |
| Update to the newest image | docker compose pull openclaw-gateway && docker compose up -d openclaw-gateway |
| Stop everything | docker compose down |
| Start again | docker compose up -d openclaw-gateway |
| Dashboard link | docker compose run --rm openclaw-cli dashboard --no-open |
| Any OpenClaw command | docker compose run --rm openclaw-cli <command> |
| Container status | docker compose ps |
Key environment variables
| Variable | What it does |
|---|---|
OPENCLAW_IMAGE | Which image to use instead of building locally |
OPENCLAW_GATEWAY_PORT | Host port for the gateway (default 18789) |
OPENCLAW_CONFIG_DIR | Host folder for config and memory (default ~/.openclaw) |
OPENCLAW_WORKSPACE_DIR | Host folder for the workspace (default ~/.openclaw/workspace) |
OPENCLAW_SANDBOX | Turns on sandboxed tool execution |
OPENCLAW_DOCKER_SOCKET | Path to the Docker socket used by the sandbox |
OPENCLAW_BROWSER_HEADLESS | Browser display mode for the browser tool |
Sandboxing agent tools with Docker
OpenClaw can run risky tools, like shell commands, inside separate throwaway containers. Turn it on with OPENCLAW_SANDBOX and point OPENCLAW_DOCKER_SOCKET at your Docker socket.
Access to the Docker socket is effectively root access on the host. The official docs say it needs explicit configuration and a security review. Only enable it on a machine dedicated to OpenClaw.
Using Podman instead of Docker? Set the sandbox backend to "podman" in your OpenClaw config.
Don't expose port 18789
A valid gateway token gives full control of your assistant. On a VPS, keep the Control UI private.
Fix common Docker problems
permission denied … docker.sockYour user can't talk to Docker. Run the commands with sudo, or add yourself to the docker group and log in again.
Build killed / out of memoryBuilding the image needs about 6 GB of RAM. Set OPENCLAW_IMAGE to a pre-built image instead.
docker-compose: command not foundOpenClaw uses Compose v2. The command is docker compose, with a space. Install the Compose plugin.
port is already allocatedSomething else is using 18789. Set OPENCLAW_GATEWAY_PORT to another port and run setup again.
Browser tool not workingThe standard image has no browser. Switch to the latest-browser image.
Lost settings after an updateCheck OPENCLAW_CONFIG_DIR points at the same host folder as before. Your data lives there, not inside the container.
More fixes: troubleshooting guide.
OpenClaw Docker questions
Is there an official OpenClaw Docker image?
Yes. The official image is ghcr.io/openclaw/openclaw, with a latest tag and a latest-browser tag that includes Chromium. Docker Hub has a mirror at openclaw/openclaw.
How much RAM does OpenClaw need in Docker?
Building the image yourself needs at least 6 GB of RAM. Using a pre-built image with OPENCLAW_IMAGE avoids the build and works on smaller machines.
How do I update OpenClaw in Docker?
Run docker compose pull openclaw-gateway, then docker compose up -d openclaw-gateway. Your settings and memory are kept because they live in host folders.
Where is my OpenClaw gateway token in Docker?
The setup script generates a gateway token and writes it to the .env file in your openclaw folder. Keep that file private.
How do I run OpenClaw commands in Docker?
Use the CLI container: docker compose run --rm openclaw-cli followed by the command, for example channels add or dashboard --no-open.
Can I use Podman instead of Docker?
Yes. Podman is supported as an alternative. If you use sandboxing, set the sandbox backend to podman in your OpenClaw config.