Deploy OpenClaw Private Gateway
Private OpenClaw Gateway, reachable only over your Tailscale tailnet
Just deployed
/data
Just deployed
/var/lib/tailscale
Deploy and Host OpenClaw Private Gateway on Railway
OpenClaw Private Gateway runs your own OpenClaw Gateway on Railway, reachable only from your Tailscale tailnet. There is no public domain, no setup web server, and no proxy in front of the Gateway. The macOS app, the dashboard, and your phone connect to it privately over Tailscale.
About Hosting OpenClaw Private Gateway
This template starts two services in one project:
- openclaw runs the official OpenClaw image (a pinned release) with the Gateway as its only process. All state lives on a volume at
/data. Token authentication and device pairing are always on, and a fresh deployment passesopenclaw security auditwith no findings. - tailscale runs the official Tailscale container in userspace mode, with no extra privileges. It joins your tailnet as
openclawand forwards raw TCP to the Gateway over Railway's private network, with HTTPS from your tailnet's certificate.
Before you deploy, turn on MagicDNS and HTTPS certificates in the Tailscale admin console, note your tailnet's DNS name (for example tail1234.ts.net), and generate an auth key (not reusable, not ephemeral). The template asks for:
| Variable | Value |
|---|---|
OPENCLAW_PUBLIC_ORIGIN | https://openclaw..ts.net |
TS_AUTHKEY | your Tailscale auth key |
OPENCLAW_GATEWAY_TOKEN is generated for you; copy it from the openclaw service's Variables to connect clients. After deploying, add your model provider's API key, run one onboarding command over railway ssh, and pair the macOS app. The Quickstart has every command.
Common Use Cases
- A personal AI assistant that is always on, reachable from your Mac, phone, and Telegram, and never exposed to the internet.
- Replacing an OpenClaw setup that sat behind a public domain, extra login, or custom proxy.
- Running OpenClaw agents and automations on managed infrastructure instead of a home server.
Dependencies for OpenClaw Private Gateway Hosting
- A Railway account on a paid plan (two services with volumes).
- A Tailscale tailnet with MagicDNS and HTTPS certificates enabled, and an auth key.
- An API key for your model provider (for example Anthropic or OpenAI), added after deploy.
Implementation Details
Both services build from github.com/stevekinney/openclaw-railway-template. The openclaw image is the official ghcr.io/openclaw/openclaw release pinned by digest, plus a small entrypoint that prepares the volume, writes a baseline config on first boot only, and drops root privileges. The tailscale service builds from the repo's tailscale/ directory with the official tailscale/tailscale image. Upgrades are a one-line version change in the repository. The repository's docs cover the architecture, security model, upgrades, and troubleshooting.
Why Deploy OpenClaw Private Gateway on Railway?
Railway is a singular platform to deploy your infrastructure stack. Railway will host your infrastructure so you don't have to deal with configuration, while allowing you to vertically and horizontally scale it.
By deploying OpenClaw Private Gateway on Railway, you are one step closer to supporting a complete full-stack application with minimal burden. Host your servers, databases, AI agents, and more on Railway.
Template Content
OPENCLAW_PUBLIC_ORIGIN
TS_AUTHKEY
