A gateway per customer
Each OpenClaw customer runs in an independent Docker container. Separate config, filesystem, credentials, and resource allocation.
OpenClaw is powerful software. Hosting it for customers needs careful isolation, predictable resources, and operations that recover cleanly.
Each OpenClaw customer runs in an independent Docker container. Separate config, filesystem, credentials, and resource allocation.
A dedicated volume follows the instance through restarts and container rebuilds. Your agent keeps its configuration and local state.
Payment webhooks create durable, retryable jobs. Requests return quickly while workers select capacity and provision in the background.
Operators create plans from the admin console. Resource limits are copied into each purchase so later edits do not alter existing instances.
Unhealthy and maintenance nodes are removed from placement. A reconciler compares control-plane state with Docker and reports drift.
Every gateway has its own bridge network. The trusted reverse proxy joins only the customer network it needs to route.
Customers never receive host access or a Docker socket. Worker nodes use mutual TLS, containers run with dropped Linux capabilities and no-new-privileges, and provider credentials are encrypted in the control-plane database.
Customer APIs filter every customer-owned record through the authenticated tenant.
Only the platform reverse proxy can reach the gateway port; container ports are never published to the host.
Administrative node changes and provisioning attempts leave timestamped records.