Skip to content
BotServBotServ
OpenClawProxmox VEAI AgentSelf-HostingLXCVMTailscaleMac-Pro-TrashcanAMD-GPU

Install OpenClaw on Proxmox VE

Self-host OpenClaw AI assistant on Proxmox VE. LXC, VM, installation, networking, security and troubleshooting.

S

schutzgeist

11 min read
Install OpenClaw on Proxmox VE

Installing OpenClaw on Proxmox VE

What This Article Covers

  • What OpenClaw is and what it’s used for.
  • How to run OpenClaw on Proxmox VE in a VM or LXC container.
  • Resource requirements for the gateway.
  • Securing your network, firewall, and Tailscale setup.
  • Configuring models, channels, and tools.
  • Tips for backups, snapshots, and common pitfalls.

Introduction: OpenClaw on Proxmox VE

OpenClaw is an open-source gateway for AI agents. It bridges voice and chat channels like Discord, Telegram, Slack, WhatsApp, Matrix, Signal, and more to local or hosted models. The gateway runs as its own service and can execute tools, skills, and plugins. Running OpenClaw on Proxmox VE gives you isolation, snapshots, backups, and straightforward resource management.

Proxmox VE works particularly well for OpenClaw because you can isolate the assistant in its own container or VM separate from other systems. This matters because OpenClaw can execute shell commands, access the filesystem, and perform other actions. An isolated environment protects the rest of your network if something goes wrong.

What Is OpenClaw?

OpenClaw is a self-hosted AI assistant gateway. It provides:

  • Multi-Channel: One gateway serves multiple messaging platforms simultaneously.
  • Tool Use: Agents can execute local commands and tools.
  • Model Providers: Integration with local models via Ollama or hosted APIs.
  • Sessions and Memory: Conversations and context persist across multiple messages.
  • Skills and Plugins: Extensible capabilities for specific tasks.
  • Sandboxing: Commands can run in isolated environments.

OpenClaw targets developers, power users, and self-hosters who want to run their own always-on AI assistant. It has a steeper learning curve than simple chatbots for absolute beginners.

Why Proxmox VE?

Benefits of Proxmox for OpenClaw:

  • Isolation: A VM or LXC separates OpenClaw from the rest of your network.
  • Snapshots: Save a system state before updates or experiments.
  • Backups: Regular backups of your VM or container.
  • Resource Management: Adjust CPU, RAM, and disk easily.
  • GPU Passthrough: Optional local models can run on GPU.
  • Firewall: Built-in firewall controls access.

LXC or VM?

LXC

  • Advantages: Low overhead, fast boot, simple snapshots.
  • Disadvantages: Shares the kernel with the host, slightly weaker isolation.
  • Recommended for: Personal or small team assistants, pure gateway use.

VM

  • Advantages: Own kernel, better isolation, GPU passthrough easier.
  • Disadvantages: More overhead, longer boot time.
  • Recommended for: Enterprise environments, GPU workloads, higher security requirements.

For most homelab scenarios, an unprivileged LXC is sufficient. If you need GPU passthrough or maximum isolation, choose a VM.

Hardware Requirements

Hardware depends on whether OpenClaw acts only as a gateway or also hosts models locally.

Gateway Only

  • CPU: 2 to 4 vCPUs.
  • RAM: 4 to 8 GB.
  • Disk: 20 to 40 GB.
  • Network: Internet access for API providers and channel updates.

Gateway with Local Model

  • CPU: 4 to 8 vCPUs, depending on the model.
  • RAM: 8 to 32 GB, depending on model size.
  • Disk: 80 to 200 GB, depending on the number of models.
  • GPU: Optional, but strongly recommended for larger models.

To start, 4 vCPUs, 8 GB RAM, and 40 GB disk are sufficient. Small 7B or 8B local models will run slowly but functionally.

Hardware Example: Mac Pro Trashcan

The following real-world test was conducted on a Mac Pro Trashcan:

root@pve:~# lspci | grep -Ei 'vga|3d|display'
02:00.0 VGA compatible controller: Advanced Micro Devices, Inc. [AMD/ATI] Tahiti LE [Radeon HD 7870 XT]
06:00.0 VGA compatible controller: Advanced Micro Devices, Inc. [AMD/ATI] Tahiti LE [Radeon HD 7870 XT]

These two AMD Radeon HD 7870 XT cards are based on the older GCN 1.0 architecture (Tahiti LE). ROCm does not support them. This means Ollama and other local AI workloads on this host currently run on the CPU. GPU passthrough in Proxmox is theoretically possible but provides no acceleration for LLM inference. If you want accelerated local inference, you need newer AMD GPUs with ROCm support or an NVIDIA GPU.

The OpenClaw LXC was created with 31 GB RAM and multiple vCPUs, which is sufficient for a pure gateway plus a small CPU-based model.

LXC Installation on Proxmox

1. Download Ubuntu Template

Make sure an Ubuntu 24.04 LXC template is available:

pveam update
pveam available | grep ubuntu-24.04
pveam download local ubuntu-24.04-standard_24.04-1_amd64.tar.zst

2. Create LXC

Create an unprivileged container with appropriate resources:

pct create 300 /var/lib/vz/template/cache/ubuntu-24.04-standard_24.04-1_amd64.tar.zst \
  --hostname openclaw \
  --storage local-zfs \
  --rootfs 40 \
  --memory 8192 \
  --cores 4 \
  --net0 name=eth0,bridge=vmbr0,ip=dhcp

3. Start Container

pct start 300
pct exec 300 -- bash

4. Install Basic Packages

apt update && apt upgrade -y
apt install -y curl wget git build-essential

5. Install Node.js

OpenClaw requires Node.js 22.22.3 or newer. For now, install Node.js 26:

curl -fsSL https://deb.nodesource.com/setup_26.x | bash -
apt install -y nodejs

6. Install OpenClaw

Follow the official installation instructions. The fastest approach is the official installer:

bash -c "$(curl -fsSL https://openclaw.ai/install.sh)"

If you prefer to use a community-maintained automated installer, there’s also a Proxmox installation script:

bash -c "$(wget -qLO - https://raw.githubusercontent.com/Ninso112/proxmox-openclaw-installer/master/install_openclaw.sh)"

7. Start Gateway

After installation, start the gateway:

openclaw-gateway

Initial setup runs through the web interface or command line.

Real-World Example: Installation in a Proxmox LXC

The following walkthrough shows an actual installation in an unprivileged LXC under Proxmox VE 7.0.2. The container is configured with 31 GB RAM.

System Information

root@Agents:~# uname -a
Linux Agents 7.0.2-6-pve #1 SMP PREEMPT_DYNAMIC PMX 7.0.2-6 (2026-05-20T08:55Z) x86_64 GNU/Linux

root@Agents:~# free -h
               total        used        free      shared  buff/cache   available
Mem:            31Gi        21Mi        30Gi        76Ki       418Mi        31Gi
Swap:          2.0Gi          0B       2.0Gi

Update Packages

root@Agents:~# apt update && apt full-upgrade -y
Hit:1 http://security.debian.org trixie-security InRelease
Hit:2 http://deb.debian.org/debian trixie InRelease
Hit:3 http://deb.debian.org/debian trixie-updates InRelease
All packages are up to date.
Summary:
  Upgrading: 0, Installing: 0, Removing: 0, Not Upgrading: 0

Installing OpenClaw

root@Agents:~# curl -fsSL --proto '=https' --tlsv1.2 https://openclaw.ai/install.sh | bash

Sample output excerpt:

Preparing installer interface...

OpenClaw Installer
Ah, the fruit tree company!

Detected: linux

Install plan
OS: linux
Install method: npm
Requested version: latest

[1/3] Preparing environment
 Node.js not found, installing it now
 Installing Linux build tools (make/g++/cmake/python3)
 Updating package index
 Installing build tools
 Build tools installed
 Installing Node.js via NodeSource
 Downloading NodeSource setup script
 Configuring NodeSource repository
 Installing Node.js
 Node.js v24.20.0 installed
 Active Node.js: v24.20.0 (/usr/bin/node)
 Active npm: 11.19.0 (/usr/bin/npm)

[2/3] Installing OpenClaw
 Git already installed
 Installing OpenClaw v2026.9.2
 Installing OpenClaw package
 OpenClaw npm package installed
 Published openclaw bin link at /usr/bin/openclaw
 OpenClaw installed

[3/3] Finalizing setup

OpenClaw installed successfully (2026.9.2)!
Installation complete. Your productivity is about to get weird.

Starting setup

OpenClaw 2026.9.2 (3928bad)
It's not "failing," it's "discovering new ways to configure the same thing wrong."

Setup Wizard

The interactive setup wizard prompts for security acknowledgment, an agent name, and a provider. This example skips the provider to configure it manually later:

Setup choices
  For the full step-by-step wizard, run `openclaw onboard --classic`.

Security disclaimer
  OpenClaw runs an AI agent with real access to this machine.
  https://docs.openclaw.ai/gateway/security

How would you like to start?
  Custom setup

I understand this is personal-by-default and shared/multi-user use requires lock-down. Continue?
  Yes

Help make OpenClaw better?
  No thanks

What should we call your first agent?
  AgentSmith

How should I set things up?
  Full access: find everything automatically

AI detection complete.

AI found
  No existing AI access was detected on this machine.

Recommended installs
  Ollama: Run open models locally
  LM Studio: Local model desktop app
  Claude Code: Anthropic's coding agent CLI
  Codex CLI: OpenAI's coding agent CLI

Model/auth provider
  OpenRouter

OpenRouter auth method
  Back

Model/auth provider
  Skip for now

Next steps
  Workspace: /root/.openclaw/workspace
  Add AI later: re-run `openclaw onboard`
  After AI connects, add a channel: `openclaw channels add`
  Open the dashboard: `openclaw dashboard`

Target Architecture

After initial setup, the LXC should be structured as follows:

                 Proxmox
                    |
              Agents (LXC)
                    |
          +---------+---------+
          |                   |
      OpenClaw              Ollama
          |                   |
          |             local LLM
          |
          +-- Claude API
          |
          +-- local model

The next steps would be:

  1. Create a dedicated agent user.
  2. Move the OpenClaw workspace from /root to the user directory.
  3. Configure the Claude API key.
  4. Install Ollama.
  5. Test a local model.
  6. Use OpenClaw between Claude and Ollama.
  7. Create a second LXC for OpenHands.

VM Installation on Proxmox

1. Upload Ubuntu ISO

Download an Ubuntu Server 24.04 LTS ISO to Proxmox and create a new VM.

2. VM Configuration

Recommended settings:

  • Machine: q35
  • CPU type: host
  • Disk bus: VirtIO SCSI
  • NIC model: VirtIO
  • QEMU Guest Agent: Enable
  • CPU: 4 vCPUs
  • RAM: 8 GB
  • Disk: 40 GB

3. Install Ubuntu

Start the VM and install Ubuntu Server. Enable OpenSSH.

4. Basic Packages and Node.js

Follow steps 4 through 6 from the LXC section.

Networking and Access

Default Binding

OpenClaw binds the gateway to 127.0.0.1 or 0.0.0.0 by default, depending on the version. For security, restrict the gateway to local or Tailscale-only access.

Tailscale provides the simplest way to securely access OpenClaw from outside your LAN:

  1. Install Tailscale in the LXC or VM:
curl -fsSL https://tailscale.com/install.sh | sh
sudo tailscale up
  1. Complete authentication.
  2. Connect using your Tailscale IP.

Tailscale eliminates the need to expose ports publicly.

SSH Tunneling

Alternative if you don’t use Tailscale:

ssh -L 8080:localhost:8080 user@openclaw-host

The gateway is then accessible at http://localhost:8080 on your local machine.

Firewall and Security

OpenClaw can execute powerful tools, so isolation is critical.

Proxmox Firewall

Enable the firewall at the datacenter level and set rules on the VM or LXC:

  1. Enable the firewall at the datacenter level.
  2. Restrict inbound connections on the container or VM.
  3. Allow only necessary ports, such as SSH, Tailscale, and the OpenClaw gateway port.

For the OpenClaw LXC or VM:

IN ACCEPT -p tcp -dport 22 -s 10.0.0.0/24
IN ACCEPT -p udp -dport 41641
IN DROP

The exact syntax depends on your Proxmox firewall version.

Enable Sandboxing

OpenClaw supports sandboxing. Commands should run in Docker, Podman, or an isolated shell:

export OPENCLAW_SANDBOX=1

No Public Ports

The gateway should not be directly accessible from the internet. Use Tailscale, VPN, or SSH tunneling instead.

Configuring Model Providers

OpenClaw works with hosted or local models.

Hosted APIs

Add a provider like OpenAI, Anthropic, or an OpenAI-compatible service in the gateway or configuration:

openclaw provider add openai --api-key DEIN_KEY

Local Models with Ollama

Install Ollama in the same LXC, VM, or a separate container:

curl -fsSL https://ollama.com/install.sh | sh
ollama pull llama3.1:8b

Configure OpenClaw to reach Ollama over your internal network, for example http://ollama.lan:11434.

Model Selection

A 7B or 8B model works well for initial tests. For better results on complex tasks, use models from 14B upward if you have sufficient VRAM.

Connecting Channels

OpenClaw can serve multiple messaging services simultaneously. Each channel is configured as a plugin.

Typical channels include:

  • Discord
  • Telegram
  • Slack
  • WhatsApp
  • Matrix
  • Signal
  • iMessage
  • Google Chat
  • Microsoft Teams
  • WebChat

Configuration happens via the Control UI, the TUI, or configuration files. Each channel typically requires a token or API credentials.

Backup and Snapshots

Snapshots

Create a snapshot before updates or major changes:

pct snapshot 300 vor-update

For a VM:

qm snapshot 300 vor-update

Backups

Regular backups using the Proxmox Backup system preserve the state of your LXC or VM. Important OpenClaw data resides in the gateway’s workspace directory, usually under ~/.openclaw or your configured workspace path.

What Should Be Backed Up

  • Configuration files
  • Workspace and state
  • Session logs
  • Installed plugins and skills
  • Channel tokens

GPU Passthrough for Local Models

When running models locally with OpenClaw, you can pass a GPU into the VM. GPU passthrough is also possible with LXC, but it’s more complex and depends on the host driver.

VM with GPU

  1. Pass the PCIe device from Proxmox into the VM.
  2. Install NVIDIA or AMD drivers in the VM.
  3. Start Ollama with GPU support.
  4. Point OpenClaw to Ollama running in the same guest or over the network.

If you’re only running as a gateway without local models, no GPU is needed.

Note on Older AMD GPUs

Some older AMD cards, like the Radeon HD 7870 XT (Tahiti LE, GCN 1.0), aren’t supported by ROCm. In the Mac Pro Trashcan we tested, Proxmox recognized both GPUs, but passthrough didn’t accelerate Ollama or PyTorch. Models ran on the CPU instead. For GPU-accelerated local models, you’ll need newer AMD GPUs with ROCm support or NVIDIA cards.

Key Terms

  • Gateway: The central OpenClaw process.
  • Channel Plugin: Connection to a messaging service.
  • Model Provider: Source for the language model.
  • Sandbox: Isolated execution environment for tools.
  • Skill: Pre-configured capability.
  • Workspace: Gateway’s working directory.
  • Control UI: Web interface for configuration.
  • TUI: Terminal interface.

Use Cases

Personal Assistant

OpenClaw runs on Proxmox, accessible via Telegram or Discord, and handles simple automations.

Team Agent

Multiple team members access a shared gateway. Permissions and channels are managed centrally.

Development Assistant

OpenClaw connects to a local code repository, runs build commands, and sends status updates over Slack or Discord.

Common Pitfalls

  • Wrong Node.js version: OpenClaw requires Node.js 22.22.3 or newer.
  • Firewall blocks Tailscale: UDP port 41641 must be allowed.
  • No isolation: Running OpenClaw on your main machine is risky.
  • Missing permissions in LXC: Unprivileged containers sometimes need extra rights for networking or device access.
  • Models unreachable: Ollama URL or API key is wrong.
  • Tokens in backups: Storing secret keys unencrypted.
  • Forgotten snapshots: Not creating a snapshot before updates.

Further Resources

FAQ: OpenClaw on Proxmox

Do I need a GPU? No, if you’re only using hosted APIs. For larger local models, a GPU is recommended.

Can I run OpenClaw in Docker on Proxmox? Yes, Docker works in both LXC and VMs. LXC may require extra permissions.

Is an LXC secure enough? For a homelab and personal use, usually yes. For higher security requirements or GPU passthrough, a VM is better.

Which channels work with OpenClaw? Discord, Telegram, Slack, WhatsApp, Matrix, Signal, iMessage, Google Chat, Microsoft Teams, and WebChat.

Can I combine OpenClaw with Ollama? Yes, Ollama can run in the same guest or in a separate container.

How do I access it from outside? Best via Tailscale, SSH tunnel, or VPN.

Sources and Further Reading

Summary: OpenClaw on Proxmox VE

OpenClaw is a versatile gateway for self-hosted AI agents. On Proxmox VE, you can run it isolated in a VM or LXC. This article walks through a real installation on Proxmox VE 7.0.2 in an LXC with 31 GB of RAM, covering Node.js setup, OpenClaw configuration, and the setup wizard. We also covered the Mac Pro Trashcan hardware example with two AMD Radeon HD 7870 XT cards, which ROCm doesn’t support, so local models run on the CPU instead. Key requirements include adequate resources, the correct Node.js version, network security via firewall and Tailscale, sandboxing for tools, and regular backups. Combining OpenClaw with Ollama gives you a local, extensible assistant for messaging, automation, and coding.

Back to Blog
Share:

Related Posts