Skip to content
BotServBotServ
OpenClawOllamaAnthropic ClaudeProxmoxLXCAI Agent

OpenClaw with Ollama and Claude on Proxmox

Connect OpenClaw on Proxmox with Claude API and Ollama fallback. User migration, systemd setup, and security.

S

schutzgeist

4 min read
OpenClaw with Ollama and Claude on Proxmox

OpenClaw with Ollama and Claude on Proxmox

What this article covers

  • How to configure OpenClaw after installation on Proxmox
  • Why a dedicated user account matters
  • Setting up the Anthropic Claude API
  • Installing Ollama in the same or a separate LXC
  • Using Claude as your primary model with Ollama as a fallback
  • Creating a Systemd service and Tailscale access

Introduction: OpenClaw with Ollama and Claude on Proxmox

Once you’ve installed OpenClaw on a Proxmox LXC, the real work begins: creating a dedicated agent user, connecting to the Claude API, configuring your local Ollama instance, and securing everything. This hybrid approach gives you the best of both worlds. Claude handles complex reasoning tasks while Ollama takes on local, privacy-sensitive, or fallback workloads.

This guide builds on the OpenClaw installation protocol and shows how to run OpenClaw on Proxmox in a production-ready way.

Key concepts

  • Agent user: A dedicated Linux user account for OpenClaw
  • Anthropic Claude API: Hosted language model service from Anthropic
  • Ollama: Locally deployed model platform
  • Fallback: Alternative model when the primary is unavailable
  • Gateway: OpenClaw’s network interface
  • Systemd: Linux service management
  • Tailscale: Mesh VPN for secure remote access

Architecture

                 Proxmox
                    │
              Agents (LXC)
                    │
          ┌─────────┴─────────┐
          │                   │
      OpenClaw              Ollama
          │                   │
          │             local LLM
          │
          ├── Claude API
          │
          └── local model

OpenClaw and Ollama can run in the same LXC or in separate containers. Starting with both in one container is simpler; you can split them later if needed.

Dedicated user account

Never run OpenClaw as root. A dedicated user improves security:

useradd -m -s /bin/bash openclaw
usermod -aG sudo openclaw

Move the existing configuration from /root/.openclaw:

mv /root/.openclaw /home/openclaw/.openclaw
chown -R openclaw:openclaw /home/openclaw/.openclaw

Switch to the new user:

su - openclaw

Setting up Claude API

Generate an API key at Anthropic and set it as an environment variable:

export ANTHROPIC_API_KEY="YOUR_ANTHROPIC_API_KEY"

For persistent use, add it to your profile:

echo 'export ANTHROPIC_API_KEY="YOUR_ANTHROPIC_API_KEY"' >> ~/.profile
source ~/.profile

Connect OpenClaw to Claude:

openclaw onboard --non-interactive --accept-risk \
  --auth-choice apiKey \
  --anthropic-api-key "$ANTHROPIC_API_KEY" \
  --gateway-bind loopback

The gateway binds to 127.0.0.1 only.

Installing Ollama

Install Ollama for local model serving:

curl -fsSL https://ollama.com/install.sh | sh

Pull and test a model:

ollama pull llama3.1:8b
ollama run llama3.1:8b

Ollama runs on port 11434 by default.

Connecting Ollama to OpenClaw

OpenClaw communicates with Ollama via its native endpoint, not the OpenAI-compatible /v1 path. The correct URL is:

http://127.0.0.1:11434

Not this:

http://127.0.0.1:11434/v1

Configuration:

openclaw config set models.providers.ollama.apiKey "ollama-local"
openclaw config set models.providers.ollama.baseUrl "http://127.0.0.1:11434"

Test the connection:

openclaw models list --provider ollama
openclaw models status

Setting primary model and fallback

Configure Claude as primary with Ollama as fallback:

openclaw config set models.default.primary "anthropic/claude-opus-4-8"
openclaw config set models.default.fallbacks '["ollama/llama3.1:8b"]'

If Claude becomes unavailable or fails, OpenClaw switches to the local Ollama model.

Ollama in a separate LXC

For better isolation, run Ollama in its own LXC and connect via internal IP:

openclaw config set models.providers.ollama.baseUrl "http://192.168.1.51:11434"

Ensure your firewall rules allow port 11434 between LXCs. Ollama has no built-in authentication, so restrict access to your internal network and ideally protect it with Tailscale.

Systemd service

Set up a Systemd service so OpenClaw restarts automatically. Store the API key in a separate environment file with restricted permissions instead of embedding it in the service unit.

sudo mkdir -p /etc/openclaw
sudo tee /etc/openclaw/environment <<EOF
ANTHROPIC_API_KEY=YOUR_ANTHROPIC_API_KEY
EOF
sudo chmod 600 /etc/openclaw/environment
sudo chown root:root /etc/openclaw/environment

Create the service file:

sudo tee /etc/systemd/system/openclaw.service <<EOF
[Unit]
Description=OpenClaw Agent Gateway
After=network.target

[Service]
Type=simple
User=openclaw
Group=openclaw
EnvironmentFile=/etc/openclaw/environment
WorkingDirectory=/home/openclaw
ExecStart=/usr/bin/openclaw gateway
Restart=on-failure
RestartSec=10

[Install]
WantedBy=multi-user.target
EOF

Enable and start the service:

sudo systemctl daemon-reload
sudo systemctl enable openclaw
sudo systemctl start openclaw

Security

  • Non-root user: OpenClaw runs under a dedicated account, not root
  • Loopback gateway: The gateway binds to localhost only, not accessible from the network
  • API key in environment file: Protect the file with 600 permissions
  • Ollama not exposed: Keep port 11434 off the internet
  • Use Tailscale: Access remotely through a private mesh network
  • Proxmox firewall: Allow only necessary ports between LXCs
  • Snapshots before updates: Save your LXC state before changes
  • Regular audits: Run openclaw security audit --deep periodically

Hardware constraints

A Mac Pro Trashcan with AMD Radeon HD 7870 XT can’t use GPU-accelerated AI because those GCN 1.0 GPUs lack ROCm support. Ollama runs on CPU instead. Small 7B or 8B models perform acceptably, but larger models are slow.

Further reading

FAQ: OpenClaw with Ollama and Claude

Does Ollama have to run in the same LXC? No, it can run in a separate LXC or even on another host.

Is the OpenAI-compatible Ollama endpoint correct? No, OpenClaw uses the native Ollama endpoint at http://host:11434.

How secure is OpenClaw? Only as secure as your configuration. A dedicated user, loopback gateway, and firewall rules are essential.

What happens if Claude becomes unreachable? If you’ve configured a fallback, OpenClaw uses the local Ollama model.

Should I add OpenClaw to autostart? Yes, if you want a persistent agent. Use a Systemd service with a dedicated user account.

Sources and further reading

Summary: OpenClaw with Ollama and Claude on Proxmox

Running OpenClaw on Proxmox with Claude and Ollama gives you a hybrid AI agent setup. After installation, migrate to a dedicated user, configure the Claude API, point OpenClaw to your local Ollama endpoint, and define fallback models. A Systemd service with a protected environment file, a loopback-bound gateway, and Tailscale for remote access improve both security and reliability. On older AMD hardware like the Mac Pro Trashcan, you’re limited to CPU inference, but that’s workable for smaller models.

Back to Blog
Share:

Related Posts