HomeVideos

How to set up OpenClaw securely (tutorial)

Now Playing

How to set up OpenClaw securely (tutorial)

Transcript

975 segments

0:00

We are talking open claw today. What can

0:02

people expect if they watch to the end

0:04

of this conversation? [music]

0:05

>> We'll cover the basics. What's openclaw?

0:07

The prerequisites.

0:08

>> Do you think the comparison [music] of

0:10

openclaw to Jarvis from Iron Man is an

0:14

apt comparison?

0:15

>> We'll find out when we look at the names

0:17

of my Hner servers.

0:20

>> I feel [clears throat] like a proud

0:20

parent right now. And how profound is

0:23

OpenClaw in terms of what it offers to

0:25

people? The thing with OpenClaw that

0:28

made it catch fire was

0:32

CJ Hes. Welcome to the show.

0:34

>> Alex Lieberman, thank you for having me.

0:36

>> Okay, so we are talking Open Claw today.

0:40

What can people expect if they watch to

0:42

the end of this conversation?

0:43

>> Yeah. So, we've prepped kind of a guide

0:45

here that we're going to walk through

0:46

today. Um, we'll cover the basics,

0:48

what's openclaw, the prerequisites. Then

0:51

really, we want to go zero to one with

0:54

having an openclaw setup without

0:56

spending a ton of money on a Mac Mini or

0:58

wasting a bunch of time trying to do it

1:00

through some provider. This is going to

1:01

be the bare metal guide to do it safely

1:03

and securely on a VPS through Hzner for

1:07

as little as five bucks a month. Um then

1:10

we're going to get an open cloth set up

1:11

and we're going to start to play around

1:13

with it. And then hopefully at the end

1:15

um we'll have time to show a couple of

1:17

cool use cases that I've personally done

1:19

as well as some that I've seen online

1:21

and we can kind of discuss how you would

1:23

go about setting up things like that. So

1:25

prerex basically what we're going to

1:28

need VPS provider cloud but there's a

1:32

ton of providers out there. I personally

1:35

like I've used it forever. They're a

1:37

European company. So when you get

1:38

invoiced, they send you an email that

1:40

says, "Stir CJ, your bill is here." Um,

1:44

then we're going to set up this private

1:46

network that's going to be tail scale.

1:48

Um, this essentially gives you a way to

1:51

connect to each of the machines, but

1:52

without having to use the open internet

1:54

as a way to connect. Essentially makes a

1:57

walled garden of the computers that you

1:59

want to be able to connect to. We're

2:00

going to set up messaging. OpenCloud is

2:02

great because it has a ton of messaging

2:04

providers. I've been dabbling with

2:06

trying to actually transfer over to

2:07

Discord, but right now Telegram's my

2:10

main driver for my agents, so we're

2:12

going to set it up that way. It's also

2:13

the fastest and easiest. And then the

2:15

last thing is we're going to need an API

2:17

key from a popular provider.

2:19

Fortunately, Anthropic shut off the the

2:22

Claude Code subscription token, but for

2:24

this we're actually going to use a

2:25

Codeex token. So, I'll log in with my

2:27

Codeex account and then we'll have that

2:29

all set up.

2:29

>> Cool.

2:30

>> Sweet. First thing we're going to do,

2:33

going to try and speedun through this

2:35

part. Going to click here to add a

2:36

server. Really not much extra you have

2:39

to do here. You can pick from any of

2:41

these costs optimized or regular

2:43

performance. One thing to note is that

2:46

you do need a decent amount of RAM to

2:48

run OpenClaw. Four should be fine, but I

2:51

usually air on the side of caution and

2:52

grab eight. And then if you're in the

2:55

US, you're going to want to choose US

2:57

East or US West. If you're somewhere

2:59

else, you're going to want to choose

3:01

essentially the closest one to you.

3:03

These change depending on where Henner

3:05

wants to serve exactly where the box is

3:06

from. But in this case, I'm going to

3:09

choose US East. And then there's not

3:12

much more you really have to touch here.

3:15

Ubuntu is set up. You want both these

3:17

public networking ports. These are

3:19

essentially the doors for how we're

3:21

going to get into the box. And then the

3:23

only other thing that is mentioned in

3:25

this guide on how to set it up that I've

3:27

already set up is the SSH key. This is

3:30

basically the password to log into your

3:33

virtual server. Volumes, firewalls,

3:35

backups, nothing to worry about here.

3:38

Um, and sorry, just one question on SSH

3:40

key. Is that effectively the is that the

3:43

key that

3:45

>> other applications are using to get into

3:47

the server? Like who like who uses the

3:49

SSH key in this context? Yeah. So the

3:52

SSH key is basically a password between

3:55

your computer and the virtual server.

3:58

>> I see.

3:59

>> And in theory when you're open to the

4:02

open internet anything can happen. But

4:04

in theory that makes it secure so that

4:07

you can SSH and actually like log into

4:10

and then have a terminal that's inside

4:12

that virtual server and only you can do

4:16

that. Now

4:18

>> keeping anything on the open internet is

4:20

scary. So, we're going to want to lock

4:22

it down, but this is kind of that first

4:25

security measure to give you a password

4:26

to try and block people from logging

4:28

into your machine.

4:30

>> Cool.

4:31

>> Volumes, firewalls, backups, placement

4:34

groups, labels, all those we can skip

4:36

down to here. Alex, do you have a cool

4:38

name for this open claw?

4:39

>> Um,

4:41

I can't use Jarvis. Let's use Ron.

4:46

>> Love it. Ron open claw.

4:50

Sweet.

4:51

So now that we have him set up, I'm

4:55

missing something I can tell. Oh, I

4:57

didn't click up here. Great. We have

5:00

that selected. And so basically for you

5:03

to you you paid for the second tier. You

5:05

said that the user could pay for the

5:07

first tier. That'd probably be enough

5:08

RAM, but you just were you played it

5:10

safe, paid for the second one. And

5:12

that's like what? A little over 10 bucks

5:14

a month.

5:15

>> Yeah. I mean, this this will come out to

5:19

literally $9.99. You can up it. You can

5:22

go bigger, but most use cases, you

5:24

really don't need it. Um, it actually

5:26

looks like I've run out of my IPs. So,

5:29

luckily, I do have a server that is

5:33

already set up that um I have not

5:36

provisioned yet, and that is Jarvis. So,

5:39

we're going to use Jarvis here. Um, I'm

5:42

actually going to hop in here.

5:44

Again, note all these IPs should

5:47

probably get blurred, but I'm going to

5:49

hop in here, copy these IPs, and then

5:53

I'm going to hop to this claude. So, one

5:56

thing that I would recommend when you're

5:57

setting this stuff up is to actually

5:59

have a documentation folder on your

6:03

local computer. Your local computer is

6:05

going to be how you're connecting to

6:06

everything with OpenClaw through SSH.

6:10

And again, that's just logging into your

6:12

server so that you can run commands on

6:14

it. If you're not familiar with cloud

6:15

code, this might be a great time to try.

6:18

I know we already have a bunch of

6:19

resources on using Cloud Code, but I'm

6:21

going to use Cloud Code here to actually

6:23

help me do the setup. This guide that we

6:25

have back here, I've already copy and

6:26

pasted and I've given it to Claude to

6:29

say,

6:30

you know, Claude's complimenting the

6:32

chef, I guess, but um I gave it all the

6:35

instructions and what we want to do. So,

6:37

I'm going to paste in that information

6:39

about um my IP address and the name of

6:42

the box. And I'm going to say great, set

6:45

this up and tell me when we

6:51

are able to SSH into the VPS. This is

6:56

essentially saying, "All right, Claude,

6:59

I need you to log into this. Here are

7:01

the credentials. You're going to go in.

7:03

You're going to lock it down and it's

7:05

going to set up all of those security

7:07

protocols that were already um listed

7:10

above. Great.

7:11

>> And and just a question here, how does

7:12

it know cuz I basically see okay, you

7:15

set up your VPS, you you have the IP,

7:19

you have the information about like I

7:22

see you have the name, you have the IP,

7:24

you give that to Claude and you say tell

7:26

me when we were able to SSH into the

7:27

VPS. Basically, when can my computer get

7:30

access to the virtual computer? How does

7:32

it know here? Where did you give it the

7:34

direction to like start hardening? Uh is

7:36

is that just using the walk through?

7:38

Like basically the walkthrough you

7:39

provided it. It's just going on to the

7:41

next step of the walk through.

7:43

>> Yep. So Claude didn't exactly do what I

7:46

wanted it to here, but that's fine.

7:48

Right now, all it did was it tried to

7:51

make sure that we're able to SSH into

7:53

the machine. It looks like we're good to

7:55

the box is live. It's here. We can

7:58

access it. Then the next thing it's

8:00

asking me is if we want to set up tail

8:02

scale. Tail scale basically gives you

8:05

your own private internet. Um it's

8:09

secure and it allows you to connect to

8:11

different machines without being

8:13

accessible from the public internet.

8:15

This is kind of stage one of security

8:17

where we really want to isolate that VPS

8:20

and your computer so that no one just

8:23

out in the wild can actually access your

8:25

server or any of the data on it with

8:27

your open claw.

8:29

love it. So, I'm going to ask it to set

8:32

up tail scale. It's actually going to

8:34

log into that VPS, install tail scale,

8:37

and then it will shoot me back a link

8:39

where I just have to confirm it. Um, one

8:44

confirmation step after this is

8:45

installed. And then we'll essentially

8:48

have tail scale on the machine. Next

8:51

couple steps are going to cut it off

8:52

from the open internet, set it up so

8:54

that we're only connecting with tail

8:57

scale and then add some further security

8:59

measures. At that point, we'll be able

9:01

to log in and start actually setting up

9:03

open claw.

9:04

>> And so just so I understand like when

9:06

you're using tail scale, what I almost

9:08

my visual here is that it basically just

9:10

creates this like safety bubble around

9:13

your around the open claw. What what

9:17

does that mean in practice? uh does it

9:20

basically just mean that like maybe you

9:22

have a good example for what tail scale

9:24

actually does that like in context is

9:26

helpful from a security perspective?

9:28

>> Mhm. So essentially the way that SSH

9:32

works is it lets us log into the machine

9:34

with that password. But when we're doing

9:36

that, we're doing that across the open

9:38

internet, which means that you know this

9:42

this virtual private server with its IP

9:46

address is accessible from the open

9:48

internet. That being said, unless you

9:50

have the password, you can't get in. But

9:53

I'm certain if we looked at that box,

9:55

it's probably getting bombarded by bots.

9:57

The second you spin something up, bots

9:59

try to attack it and they try to get in

10:01

and I've even had VPS's in the past with

10:05

nothing sensitive on them get kind of

10:07

compromised in this way. Um, I had a dev

10:10

server running once and someone put a

10:12

crypto miner on it and it it became this

10:14

whole thing but eventually I was able to

10:16

just turn it off. Um but tail scale kind

10:19

of from this diagram basically what it

10:21

does is it makes your virtual server

10:25

invisible to the public internet. So it

10:28

blocks it out and it makes sure that

10:30

only whatever devices you have on your

10:33

tail scale network can access it and

10:36

nothing else can really reach it. Plus

10:38

it's encrypted and it kind of saves you

10:40

from all just the lowhanging fruit of

10:43

security issues by having something on

10:45

the open internet.

10:46

>> Cool.

10:48

Sweet. Great. Cloud's giving me the off

10:51

link. I'm going to open this real quick.

10:54

This is probably another place to blur.

10:58

Great. We're connected. Oh, amazing. And

11:01

Claude's just taking it away. Great. So

11:03

now what's happening here is we actually

11:06

get a new IP address for Jarvis

11:10

that is on the tail scale network as

11:14

opposed to the open internet. So

11:16

essentially it's we had an address that

11:18

was open to everyone. Think of it as the

11:21

address of your house, but it's on

11:23

Google Maps.

11:24

Now Jarvis is in a gated community and

11:27

no one else knows who he where he lives

11:30

except for the other people in the

11:31

community. No one in the public knows

11:34

this address or can even access it.

11:36

>> Love it. Great. It's like that gated

11:39

community in the Bahamas where all the

11:40

celebrities live and no one else knows

11:42

who's there other than the other

11:43

celebrities.

11:44

>> Exactly. Jarvis. Jarvis is a celebrity

11:47

now.

11:49

Cool. Going to try and log into him

11:51

here. In the meantime, kind of want to

11:53

hop to some of these other concepts and

11:57

just like best practices to harden the

12:00

server and what we're going to do here.

12:02

I don't think we're going to go through

12:03

all of these just to avoid all the

12:05

config and setup and hoops to jump

12:07

through, but unfortunately, you do kind

12:10

of have to take those steps to actually

12:13

make this truly secure. All of these

12:14

steps are kind of classic cyber security

12:17

principles. And one thing I even like to

12:18

do occasionally is I run a codeex and I

12:21

say codeex

12:23

red team these boxes. Try and get in.

12:26

Try and break in. Find any security flaw

12:28

you can. And it's actually been really

12:30

good at saying hey I wasn't able to get

12:33

in but here's a place where you have a

12:36

lot of attack surface and here's how you

12:38

can harden it. Um and I'm no, you know,

12:41

expert in the security stuff. I know the

12:43

basics, but it's been really helpful in

12:45

giving me confidence that we've fully

12:47

secured this VPS and that no one else

12:49

can get it.

12:50

>> So, we're going to show the share this

12:51

in the show notes, but just because I

12:53

know you're going you don't want to go

12:55

deep in all of the security hardening

12:56

stuff for someone like I saw one of the

12:59

things is automatic security updates.

13:01

Another one is firewall. How should

13:02

people be setting this up since you're

13:04

not going through each one right now? Is

13:06

it literally as simple as just like if

13:08

they tell Claude to ingest this guide

13:10

and do it, Claude will take them through

13:12

all the steps?

13:13

>> Yeah. Yeah. I think um we can probably

13:16

go live basically right here. But um as

13:20

far as these security things go, we

13:22

won't go through line by line, nor am I

13:24

even going to have Claude set these up

13:26

on the one we just set up. But overall,

13:29

if you give these kind of guides and

13:32

descriptions, Claude will actually set

13:34

this up. And this includes a lot of

13:36

hardening. So you can kind of see in

13:38

this diagram here that we have your VPS,

13:42

this tail scale network, it's going to

13:43

block it off from the public internet.

13:46

This firewall is even going to further

13:48

block any public inbound traffic. We're

13:51

going to lock it down with SSH

13:53

hardening. This is going to give you

13:54

keys only. It's going to make sure that

13:56

traffic can only go from your computer

13:58

to the machine. Other machines can't

14:01

access each other. We're going to have

14:03

some intrusion prevention. Basically, if

14:05

some public address tries to get in, um,

14:09

we're going to use this package that

14:11

automatically bans IP addresses. And

14:13

we're going to set up auto updates on

14:15

the box so that if any new operating

14:17

system updates come out, it just

14:19

automatically stays up to date. Um,

14:22

classic security principle. No, no

14:25

single layer is bulletproof. So, we're

14:27

just going to layer them on and make

14:29

sure that this is fully secure. And

14:31

hopefully these instructions are easy

14:33

enough to just lob to Claude and have it

14:35

set everything up for you. And then you

14:38

kind of come out the end with a VPS

14:40

that's fully provisioned and secure that

14:42

only you can access.

14:44

>> Love it.

14:46

Now we're on to the fun stuff.

14:48

[laughter]

14:49

Um, it's time for Ron.

14:52

>> It's time for Ron. We're going to bring

14:53

Ron online. So what I usually do in this

14:57

step is I'll have Claude handle

15:00

installing OpenClaw, installing the

15:02

dependencies, making sure that we have

15:04

node on the um server just so that we

15:08

have everything to go or everything that

15:11

we need to actually run openclaw. And

15:13

then I'm going to log in and do the

15:14

onboarding.

15:16

>> And uh my my my friend was wondering

15:18

what is node? Uh, node is just um it's

15:23

just a fancy thing that runs code that

15:26

openclaw needs. Um, it's just a

15:28

javascript javascript runtime that um

15:32

lets you use javascript [clears throat]

15:33

code. Um, openclaw is written in

15:36

typescript. So, it needs something on

15:38

that server. Think of this computer that

15:40

we just bought this VPS as a brand new

15:43

computer that just came into this world

15:46

and it has nothing on it. So, we have to

15:48

install all the dependencies first.

15:49

Cool. I'm going to say skip the security

15:52

for now. Log in and set up node and open

15:57

claw.

15:58

Don't run setup or onboarding commands.

16:03

Just install it. Great. And then over

16:05

here, I'm going to SSH into Jarvis. This

16:08

is actually going to give us a terminal

16:10

inside Jarvis. So, we're actually on

16:13

that machine, which is pretty cool. In

16:15

here, we can run commands. We can work

16:17

with OpenClaw. We're actually going to

16:19

run the OpenClaw kind of CLI interface

16:23

and chat with the bot as we get it set

16:25

up. And this will take a second over

16:27

here. There's a nice little install

16:29

script from OpenClaw that automatically

16:32

installs all the dependencies. Um,

16:34

>> love it.

16:35

>> I have that link.

16:36

>> And for that, like did you did you have

16:38

to feed from your doc into Claude what

16:41

these install scripts were or is Claude

16:43

able to just find them? This started as

16:45

a battle of me going online and trying

16:48

to figure everything out. And then you

16:50

can see at the top, if I scroll all the

16:52

way up to the top of this chat, I

16:54

actually dumped the whole guide into it.

16:56

So, it knows all these steps from this

16:58

guide. Um, and that's been super helpful

17:00

to me in just

17:02

>> spinning up new ones quickly.

17:04

>> But it I will say the first time I set

17:07

it up, it was a bit of a maze. And

17:10

that's what we're here for today. We

17:11

want to get everyone watching set up as

17:13

fast as possible.

17:15

>> Awesome.

17:16

Sweet. So, we're in. We can now hatch

17:21

Ron/Jarvis.

17:23

>> I was going to say Ron's going through

17:24

an identity crisis ever since you had to

17:26

switch uh switch who he was in Tail

17:28

Scale, but I'm going to keep calling him

17:30

Ron.

17:30

>> Yeah, we'll go we'll go with Ron. We can

17:32

actually you get to name him. So,

17:35

um, there is a thing. It's probably not

17:39

going to show here, but they refer to it

17:41

as being hatched.

17:44

Yeah, it doesn't say on that setup

17:46

command, but when you first install

17:47

OpenClaw, it says, "How do you want to

17:49

hatch your claw?"

17:50

>> I love it.

17:52

>> So, we're going to hatch him. There's a

17:53

quick command called OpenClaw onboard.

17:56

I'm actually just going to zoom in here.

17:58

It's going to ask us a couple questions.

18:00

It's going to get us set up with our

18:01

account and then we're going to be off

18:03

to the races.

18:05

>> And just so for someone who's setting up

18:06

OpenClaw in lockep with you, do they

18:09

have to go do they have to basically go

18:11

in their terminal and do this command,

18:14

this OpenClaw onboard command within the

18:17

VPS or could you just have Claude do

18:19

this?

18:20

>> You have to do it in the VPS. So, you're

18:21

going to want to install it on the on

18:24

the VPS, log into it, and then run this.

18:27

This does take a second to boot up. And

18:29

then the reason you're going to want to

18:31

run this on the VPS and then go through

18:34

the steps there is because you need to

18:36

log into a few things. You need to make

18:37

sure that everything is set up. And

18:41

honestly, the onboarding is kind of fun.

18:43

You can just make config files and throw

18:45

them on the machine and it'll work. But

18:48

I actually quite like the experience of

18:50

going through and chatting with it the

18:51

first time to make sure it understands

18:54

who it is, who I am, and what we're

18:56

going to set up.

18:57

>> Yep.

18:59

>> Cool. Always recommend onboarding mode,

19:01

quick start. Then you've got a ton of

19:04

model providers to choose from. Um, I've

19:08

been clawed through and through, but

19:10

recently with the codeex ooth and the

19:14

codeex rate limits, like the actual

19:17

token limits that you get, I've been

19:19

preferring those for my open clause just

19:22

because I can get so much more usage.

19:24

Um, so I'm going to log in here with a

19:27

codeex token. Essentially, all of these

19:30

are going to look roughly like this

19:32

where you get some

19:35

URL to go to and then you're going to

19:38

log into whatever account you chose.

19:41

Then you're going to come back here and

19:43

paste some token. So, I'm going to hop

19:45

to this link. Once you're logged in,

19:47

you'll get a link. This is going to be a

19:49

redirect link and it's not going to work

19:51

on your computer because it's trying to

19:53

redirect to the link that actually came

19:55

from the other machine and your browser

19:58

and your computer can't exactly talk

20:00

between each other like that. So, we're

20:02

just going to copy this link and we're

20:04

actually going to give this back to the

20:06

open claw here. It's going to take that

20:09

redirect and get everything set up. You

20:13

can choose a model.

20:15

>> Is there a model that you recommend?

20:17

Yeah, I mean 5.3 codeex seems to work

20:20

really well in this open claw harness. I

20:25

did set one up with an anthropic API key

20:28

and opus I think is Opus is the goat in

20:32

agentic environments, but the problem

20:36

right now is just price. You can't use

20:38

your cloud code subscription and you're

20:40

paying a massive API price. So for me,

20:44

5.3 codeex does fine. And it's I I can't

20:48

hit my codeex usage if I want to.

20:51

>> Cool.

20:52

>> Now we get to set up our first channel.

20:54

We're going to do Telegram.

20:57

And then what's really cool is you get

20:59

some steps here. You're going to open

21:02

Telegram and actually message this

21:03

account called BotFather. And BotFather

21:07

is going to get you set up with the

21:09

Telegram integration.

21:11

So, I'm going to hop over to my

21:12

Telegram, and I've already got a

21:14

conversation with BotFather,

21:17

and I'm going to say slashnewbot.

21:21

Is Botfather owned by OpenClaw, or is

21:24

this like a

21:26

uh like a third-party

21:28

uh Telegram bot that just like people

21:30

use as a service,

21:32

>> you know? I'm not sure. I in my head it

21:36

was open. it was open claw. But thinking

21:40

about it now, I don't know if that makes

21:42

sense. I don't know if there's

21:43

>> honestly I was Yeah, that's why that's

21:45

why I was curious. I was I saw 5.9

21:47

million uh monthly users and I was

21:49

curious if those are all OpenClaw or

21:51

other other people.

21:52

>> Yeah, I I have no idea. I mean, this

21:56

this has enough functionality that I bet

21:58

it might just be a Telegram thing.

21:59

>> Yeah, cool.

22:01

>> So, we're choosing a name for the bot.

22:03

>> Ron,

22:04

>> it's going to be Ron.

22:06

Now you have to pick a like a username

22:09

for it that ends in bot. I found that

22:12

most of these are taken. So we're going

22:13

to do

22:14

>> Ron Ron Johnbot. Ron Johnbot.

22:16

>> I Ron John bot's got to be taken.

22:19

>> Wow. We got Ron John. [laughter]

22:23

>> Awesome. Cool. So now we get this token.

22:29

And this token is what actually lets us

22:32

use this to hook up our open claw to

22:36

Telegram. So I'm going to take this

22:38

token and I'm going to put it here.

22:40

That's our bot token.

22:43

And it looks like it worked fine there.

22:46

Great.

22:48

Now we're on to some of the config

22:50

stuff. So skills are super super helpful

22:54

in OpenClaw environments. Um, I kind of

22:58

skip them only because Peter has set up

23:03

so [snorts] many of these integrations

23:04

with either pieces of software that he's

23:07

worked closely with or exist or that

23:09

he's built himself. And a lot of these I

23:14

personally don't use or don't need.

23:16

Sometimes I set up the GitHub one. One

23:18

time I set up the Nano Banana one just

23:20

because I wanted it to send me more

23:22

pictures. But generally, I skip this

23:25

because you can always come back to it

23:26

and add the skills when you want and how

23:29

you want them.

23:30

>> And just to clearly break this down,

23:32

these skills that um the creator of Open

23:34

Claw created, like how should someone be

23:36

thinking about these? Like for example,

23:38

the Nano Banana Pro skill, what does

23:40

that actually do in practice? What does

23:42

that allow you to do? Yeah, any of these

23:44

skill files are just a markdown file

23:48

that kind of lay out

23:51

a a specific workflow or how to use a

23:54

tool and

23:56

kind of give the the agent guidance.

23:59

Almost think of it as like

24:01

for a human it would be a set of

24:04

instructions or a YouTube tutorial. For

24:06

the agent, it's just like a markdown

24:08

file. So there's all these like

24:11

different integrations that it can use

24:13

and work with and do things for you with

24:16

these tools. I much prefer rolling with

24:20

no skills at the start and then per claw

24:24

depending on what we're doing. I kind of

24:26

walk through a manual workflow. You

24:28

know, let's say we're we're working on

24:30

some project and we're doing a GitHub

24:32

PR.

24:34

I I would walk it through. Okay, you're

24:37

gonna make your changes. You're going to

24:39

push them. Then that's actually going to

24:42

show up in a preview deployment just

24:44

like a a preview environment. It's not

24:46

deployed on production, but it's

24:48

somewhere where you can test. Then you

24:51

can use, you know, this browser use

24:54

skill to go test it. And then once it's

24:57

tested, you can ship that to production.

24:59

So that flow I would do manually a few

25:02

times. And then I would say based on

25:04

this workflow, make a repeatable skill

25:06

for yourself. So you know this flow in

25:08

the future. And I've just found that be

25:10

much more customizable and functional

25:12

for what I want to be doing with Open

25:14

Club.

25:15

>> Cool. Awesome.

25:17

>> Cool. So we're going to skip that. Um

25:19

there's a bunch of API keys you can dump

25:21

into this to give you access to Google

25:23

Places, Nano Banana, Notion, OpenAI,

25:27

OpenAI, [laughter] 11 Labs. You know,

25:29

there's a ton of a ton of things you can

25:31

set up. Um, the 11 Labs one is kind of

25:34

cool because you can have your agent

25:35

actually talk to you. Um, but a lot of

25:39

these things are more, you know, when

25:41

you really want to get deep into the use

25:43

cases and play around with it. For our

25:45

setup, we definitely don't need these.

25:48

Now, hooks. I like to enable all of

25:52

these hooks. These hooks are very

25:54

helpful because what these do is they

25:56

automatically load context and

25:59

automatically save things like commands

26:02

or sessions that you're in to memory.

26:05

One of the other big things that

26:07

OpenClaw I think has um found a novel

26:10

approach to is long-term memory in these

26:12

agents and I think it's done a great

26:14

job. So we want to enable all of these.

26:18

>> And can you just explain what a hook is

26:20

exactly? Yeah, a hook, if you think of a

26:23

skill as a set of instructions that the

26:25

agent uses to do something, a hook is a

26:30

little piece of code. I don't have a

26:32

great analogy actually. It's a little

26:34

piece of code that runs when the agent

26:36

does something very specific. So, if we

26:39

look at boot, there's a boot.md file and

26:43

this runs when you start your claw. So

26:47

maybe every time you start it or it, you

26:49

know, kicks back into action, you want

26:52

it to do something right away when it

26:53

boots. You would put instructions in

26:55

boot empty. I see.

26:57

>> You can also have additional

26:58

instructions that come in right away.

27:00

You can also have this one that logs all

27:04

command events to a central file so that

27:07

as it's doing stuff, it's recorded

27:10

somewhere automatically. And then the

27:12

claw can actually go back and reference

27:13

that if it needs to see, hey, how did we

27:16

do this before? It can actually

27:18

reference that audit file um and then

27:20

make use of it for future.

27:23

>> I don't know. I don't know if this is

27:24

accurate or the right analogy, but

27:26

almost like when you're saying this,

27:28

what it comes off as to me is like these

27:30

are almost like

27:32

um

27:34

conditional or situational skills

27:37

relevant to like your actual computer or

27:40

like relevant to the the machine like

27:43

almost like I think of like skills in

27:44

the way you were showing them before are

27:46

relating to other applications and how

27:48

your opening claw basically acts with

27:52

and around these other applications.

27:53

Whereas like these are specific to the

27:55

open claw itself and they're conditional

27:58

based on certain events.

27:59

>> Yeah. Yeah. So these just get [snorts]

28:01

fired when things happen and sometimes

28:04

they're injecting context and sometimes

28:07

they're just saving what the claw does

28:10

so that later it can reference it.

28:11

>> Cool.

28:13

Cool. So we're in everything is set up.

28:18

What it's doing now is installing the

28:20

gateway. The gateway is essentially this

28:24

other core piece of open claw that gives

28:27

the agents a channel they can talk

28:29

through. Think of it as a big group chat

28:33

and in that group chat it can be your

28:36

telegram, your discord, your slack, but

28:39

it can also be the main agent fires off

28:42

a sub agent and the sub agent has to ask

28:44

it a question and it talks back. It's

28:46

basically this main bus where all the

28:49

communications between your main agent,

28:52

your sub agents, and you go through. And

28:54

that's what's running 24/7, kicking off

28:57

those heartbeat runs, keeping it alive,

28:59

and you know, really having it work

29:00

while you sleep. And

29:02

>> And why is that setup important? Like

29:05

why why why does that make the specific

29:09

like Open Clause specifically more

29:11

powerful? This kind of like team of

29:13

agents that are talking to each other.

29:16

So this is I think a lot of the products

29:19

and tools right now are trying to solve

29:21

this like agent collaboration

29:24

communication problem. The thing that I

29:26

love about the gateway is it's so

29:30

simple. Um I think there's actually a

29:32

diagram over here of it working. Maybe

29:36

not. I might have hallucinated that. Um

29:40

but basically this gateway is so simple

29:43

where you have your inputs. Your inputs

29:46

are either you writing from Telegram,

29:49

Discord, whatever messaging setup you've

29:52

connected. The inputs can also be other

29:55

agents and that flows through a queue.

29:58

That Q then gets picked up by the main

30:00

agent. It does something based on the

30:02

message and then it can send messages

30:04

back out. Whether that's a reply to you

30:07

on Telegram or a reply to you um on

30:10

Discord or a reply to a sub agent, it's

30:13

just this bus that lets anything come in

30:16

and then the main agent orchestrate

30:17

anything going out any of the other

30:19

channels.

30:20

>> Cool.

30:22

Okay, it's time to hatch run.

30:26

>> I do like to hatch in the the TUI. The

30:28

web UI I think could use some work. So,

30:31

if you're familiar with cloud code in

30:33

your terminal, this is going to feel

30:34

very familiar. We're going to hatch.

30:38

All that hatching does is text the bot,

30:40

wake up, my friend. [laughter]

30:42

>> I I feel I feel like a proud parent

30:44

right now.

30:45

>> I know Ron Ron is here. Um, so there's

30:49

kind of a flow that's set up in the very

30:51

beginning.

30:53

We're not going to go through like deep

30:54

deep detailed prompts in this right now,

30:57

but we have gone from zero to one and we

30:59

have an open clause setup. Um, and

31:01

following all those steps, we'd have it

31:03

on a secure box that we can only access.

31:06

And now we just kind of get to play with

31:08

our new open claw. So,

31:11

real quick, I'm just going to say

31:14

you are Ron.

31:17

You are my

31:20

personal art finder.

31:24

You are to go online

31:28

and find photos of art and send me them

31:35

and make a comprehensive profile on what

31:40

I like and don't like.

31:44

And then I'm gonna say I am actually two

31:47

people.

31:49

Oh my god.

31:52

CJ and Alex,

31:56

you should

31:59

store our art preferences

32:03

in your memory

32:06

and learn more and more over time what

32:10

we like.

32:13

And then what what vibe do you think,

32:16

Alex? [snorts]

32:17

>> I like photorealistic.

32:21

Okay. Alex likes photorealistic,

32:24

but what vibe do you want Ron to have in

32:27

his personality?

32:28

>> Oh, um,

32:31

sassy.

32:33

>> You are very sassy. [laughter]

32:37

Um, there's also a great post by Peter

32:42

on Twitter about how to get its soul up

32:46

and running. Um, and I like to say you

32:49

are very opinionated

32:52

and you act on those opinions.

32:56

Love it. Great. And we're going to kick

32:59

him off. He's going to take this, ingest

33:02

it, and hopefully we can actually get

33:04

him to run through one of these tasks.

33:06

One other thing that's always good to

33:08

test once you have this set up is

33:11

hopping over to Telegram,

33:13

clicking on Ron Johnbot. We're going to

33:17

hit start and we're going to say hi.

33:20

It is going to give you this pairing

33:22

code.

33:26

>> So just so I understand here, can you

33:28

you talking to Ron in Telegram, is that

33:31

the same as you talking to Ron in your

33:34

terminal?

33:35

>> Yeah. So that's that's the whole beauty

33:37

of the gateway. All of the messages can

33:39

come from different places and then all

33:41

of them can go out in different places

33:43

>> and Ron can actually choose it.

33:46

>> So Ron is online. Save this memory

33:48

already. He's sassy.

33:51

>> So we can give a starter profile. But

33:53

first I'm actually just going to say,

33:56

can you make sure you are configured for

34:01

Telegram?

34:03

Because now he's set up, he can run

34:06

commands.

34:07

He can actually manage himself, his own

34:10

workspace, his configuration.

34:12

>> So giving him all this information,

34:15

>> he should be able to just set this up

34:16

for us.

34:18

>> Love it.

34:20

>> Sweet. So we're good on Telegram. I'm

34:23

going to hop over here and say, "Hey,

34:24

Ron, can you hear me from Telegram?" And

34:27

he's typing. And here he is. Same bot,

34:30

different channel. And we've done it.

34:33

We've set up Ron end to end. Um, from

34:36

here, you know, my my only real tip in

34:39

your in building this up is actually

34:41

just dumping as much information about

34:44

you as you can. Really try to get it to

34:46

understand who you are, what your

34:48

preferences are. Um, and the bots are

34:50

really good at managing their internal

34:52

state to try and get you to a point

34:55

where um, it's performing better, it's

34:58

doing more for you, it's actually acting

35:00

on your behalf.

35:02

Love it. And one last question for you.

35:05

Um, is if I'm a busy professional or

35:09

executive watching this and I I've now

35:12

set up my run my open claw and I'm like,

35:16

okay, what do I do now? Like what is

35:18

actually a useful way that I can use

35:20

openclaw? Just based on you playing

35:22

around with openclaw a lot and just

35:24

understanding like what other knowledge

35:26

workers may like? like what do you think

35:27

is the lowest hanging fruit of how Ron

35:30

or their open claw could be

35:32

exceptionally helpful that let's just

35:34

say they start with one use case what is

35:36

the one use case that you think people

35:37

could feel the power of openclaw with if

35:39

they get it set up the right way

35:41

>> yeah so I like to think of it as if you

35:47

had a perfect assistant what would they

35:50

do for you and in any of those scenarios

35:53

it's going to be very custom that's what

35:55

openclaw is strong in doing these like

35:58

custom workflows. You know, the the

36:00

basics of monitoring your email,

36:02

monitoring Slack, helping you reply to

36:04

things, helping you stay on top of

36:06

stuff. I can actually show you my

36:08

personal assistant, Alfred. I had him

36:11

send me an essay that I think is about

36:12

laundry to just push our message history

36:15

up. But with Alfred, he is monitoring

36:19

kind of my Slack channels and my emails

36:22

and making sure to keep me up to date on

36:25

my to-dos. And he even has a little task

36:28

tracker of his own where I kind of made

36:31

some of this fake data. But he actually

36:34

puts things on here, messages me, keeps

36:36

me on top of things. So whatever the

36:40

simplest kind of task management way

36:43

that you can think about handling tasks,

36:47

organizing them, keeping yourself on top

36:49

of stuff, trying to offload as much of

36:51

that to the bot as possible, and then

36:54

finding where it breaks. There are

36:55

places where it's not perfect, but it

36:57

can do a lot more than I think people

36:58

give it credit if you just spend the

37:01

time to play around with it. And when it

37:03

does something wrong, ask it why it did

37:05

it wrong and what we can do to make it

37:07

do it right in the future. And the

37:09

amount of things it can self-correct is

37:11

still surprising me.

37:13

>> Love it. I feel like we we're going to

37:15

want to do a part two of this. That's is

37:17

that's all around like, okay, now that

37:19

we have OpenClaw set up, how do we

37:22

actually like if I want to configure it

37:24

to be my perfect personal assistant?

37:26

like we could probably spend like

37:28

another 45 minutes just getting it to

37:30

like be my personal assistant through my

37:32

emails, my Slacks, my texts, whatever.

37:34

So, I think that would be a good part

37:35

two for us to do.

37:37

>> Yeah, there's tons of that's kind of the

37:40

tricky part is like setting this up is

37:41

half the battle, but I think a lot of

37:43

people get to that point, have it set up

37:45

and go, now what? And there's a lot of

37:47

like places you can push it, but at the

37:49

end of the day, it is this. kind of the

37:53

first technology where it's always on

37:55

and you can customize it to whatever use

37:57

case you want, but there's a ton of

37:59

lowhanging fruit that I think is easy to

38:00

set up that can be immensely valuable to

38:03

anyone out there who's able to set this

38:05

up.

38:05

>> Love it. Anything else you want to share

38:07

before we uh finish things up?

38:09

>> No, I think that's it. I hope this is uh

38:12

helpful and I hope more and more claws

38:14

are hatched as a result of this

38:16

walkthrough.

38:17

>> Love it. CJ, thank you so much. For

38:19

those who are watching, again, look at

38:22

this as like a almost like a reference

38:24

guide. Feel free to watch the video, but

38:27

rewatch it as you're working through the

38:29

process of setting up your open claw.

38:30

We're also going to include the guide

38:32

that CJ created in the show notes, so

38:35

that one, you can reference it, but also

38:36

you can feed it to Claw to help you set

38:39

up a safe and secure OpenClaw. And then

38:41

more videos to come on specific use

38:43

cases and applications in your work uh

38:45

once you have your version of Ron set

38:47

up. Thanks so much for joining everyone

38:49

and we'll see you again soon. Later.

Interactive Summary

This video is a comprehensive tutorial on how to set up OpenClaw, an autonomous agent framework, on a secure Virtual Private Server (VPS) using Hetzner. The guest, CJ Hes, guides viewers through provisioning a server, hardening it with Tailscale for secure, private networking, and installing OpenClaw. The video also covers setting up messaging integrations, specifically with Telegram, and discusses how to train the agent with personal preferences and custom skills to act as an effective personal assistant.

Suggested questions

4 ready-made prompts