Deploy OpenClaw Private Gateway

Private OpenClaw Gateway, reachable only over your Tailscale tailnet

Deploy OpenClaw Private Gateway

/data

Deploy and Host OpenClaw Private Gateway on Railway

OpenClaw Private Gateway runs your own OpenClaw Gateway on Railway, reachable only from your Tailscale tailnet. There is no public domain and no setup web server. The macOS app, the dashboard, and your phone connect to it privately over Tailscale, with HTTPS from your tailnet's certificate.

About Hosting OpenClaw Private Gateway

This template starts one service with one volume. The openclaw service runs the official OpenClaw image (a pinned release) with Tailscale inside the same container:

  • The Gateway listens only on localhost. OpenClaw itself runs Tailscale Serve, so it appears in your tailnet as openclaw at https://openclaw.your-tailnet.ts.net, and pairing codes and the dashboard origin follow automatically.
  • On your tailnet, the dashboard signs you in with your Tailscale identity. Token authentication still protects everything else, and each device that runs the macOS app or a node is approved by hand.
  • All state (OpenClaw's config, sessions, and credentials, plus Tailscale's identity and tool logins) lives on a volume at /data.

Before you deploy, turn on MagicDNS and HTTPS certificates in the Tailscale admin console and generate an auth key (not reusable, not ephemeral). The template asks for one value:

VariableValue
TS_AUTHKEYyour Tailscale auth key, used once on first boot

OPENCLAW_GATEWAY_TOKEN is generated for you. After deploying, add your model provider, open the dashboard at https://openclaw.your-tailnet.ts.net/, and pair the macOS app. The Quickstart has every command.

Common Use Cases

  • A personal AI assistant that is always on, reachable from your Mac, phone, and Telegram, and never exposed to the internet.
  • Replacing an OpenClaw setup that sat behind a public domain, extra login, or custom proxy.
  • Running OpenClaw agents and automations on managed infrastructure instead of a home server.

Dependencies for OpenClaw Private Gateway Hosting

  • A Railway account on a paid plan (a service with a volume).
  • A Tailscale tailnet with MagicDNS and HTTPS certificates enabled, and an auth key.
  • A model provider (for example Anthropic or OpenAI), added after deploy.

Implementation Details

The service builds from github.com/stevekinney/openclaw-railway-template: the official ghcr.io/openclaw/openclaw release pinned by digest, the official Tailscale binaries pinned the same way, a small entrypoint that prepares the volume and logs Tailscale in on first boot, and a sidecar that relays only Railway's health check to the loopback-only Gateway. The image also includes optional tools for OpenClaw skills (GitHub CLI, gog for Google Workspace, Claude Code, Codex) and Homebrew on the volume. Upgrades are a one-line version change. The repository's documentation covers the architecture, security model, upgrades, and troubleshooting.

Why Deploy OpenClaw Private Gateway on Railway?

Railway is a singular platform to deploy your infrastructure stack. Railway will host your infrastructure so you don't have to deal with configuration, while allowing you to vertically and horizontally scale it.

By deploying OpenClaw Private Gateway on Railway, you are one step closer to supporting a complete full-stack application with minimal burden. Host your servers, databases, AI agents, and more on Railway.


Template Content

More templates in this category

View Template
Chat Chat
Chat Chat, your own unified chat and search to AI platform.

okisdev
116
View Template
stella
Self-host stella with web, API, Postgres, Redis, and object storage.

Jan Kubica
7
View Template
Hermes Agent | OpenClaw Alternative with Dashboard
Self-Hosted Hermes AI Agent for Telegram, Discord & Slack

codestorm
85