Howdy, Stranger!

It looks like you're new here. If you want to get involved, click one of these buttons!


Shells Virtual Desktop
BMail.ag - Secure Email Service
Server.net
CPLicense.net
VPS Server
Buy VPN
Vultr
VMs for AI
HostDare
ReliableSite White-Label Dedicated Hosting for Resellers
InterServer VPS
BMail.ag - Secure Email Service
Best VPN
High-Performance Bare Metal Server Solutions
Karvl.com
Server Mania Cloud Hosting
DataWagon Hosting
AlphaVPS Hosting
Evoxt.com
Clouvider
VPS Hosting with NVMe
Residential IPs in the US & 4G Mobile Proxies in EU & US with Unlimited Bandwidth
ReliableSite White-Label Dedicated Hosting for Resellers
Rabisu - Hosting Solutions
Shells Virtual Desktop
Home β€Ί General
New on LowEndTalk? Please Register and read our Community Rules.

All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.

Help Us Secure Self-Hosted AI: OpenClaw Setup Script (Open Source)

rarecloudrarecloud Member, Patron Provider

Hey LET,

In the beginning of 2026, security researchers found 42,000+ OpenClaw instances running exposed to the internet with zero authentication. API keys, conversations, personal data, all wide open.

We decided to fix that.

The Project

We created an open-source setup script that installs and hardens OpenClaw properly:

πŸ”— github.com/RareCloudio/openclaw-setup

It implements an 8-layer security model:

  1. nftables firewall (only SSH open)
  2. fail2ban (brute-force protection)
  3. SSH hardening (custom port, DenyUsers)
  4. Gateway token authentication
  5. AppArmor profiles
  6. Docker sandbox for agent code
  7. systemd isolation (NoNewPrivileges, ProtectSystem)
  8. Screen lock for desktop mode

The dashboard binds to localhost only; no more exposed instances.

Why We Need Your Help

We're a small team and we want this script to be bulletproof. The more eyes on the code, the better.

We're looking for:

  • πŸ”’ Security researchers β€” Find vulnerabilities, suggest hardening improvements
  • πŸ’» Developers β€” Add features, improve code quality, fix bugs
  • πŸ“ Documentation β€” Better README, tutorials, translations
  • πŸ§ͺ Testers β€” Try it on different environments, report issues
  • 🐧 Linux experts β€” Support for more distributions (currently Ubuntu 24.04 only)

What You Get

All contributors will be credited in the README:

  • Contributors section for code/docs/testing contributions
  • Security Acknowledgments for vulnerability reports
  • Sponsors section for significant contributions

We also welcome PRs, issues, and discussions on GitHub.

How to Contribute

  1. Check out the repo: github.com/RareCloudio/openclaw-setup
  2. Read CONTRIBUTING.md
  3. For security issues, email [email protected] (see SECURITY.md)
  4. For everything else, open an issue or PR

Questions? Ideas? Roast our code? Let us know below. πŸ‘‡


Links:

A Note Before the Comments Roll In

We know how LET works. Someone will say this is just marketing, someone else will say the project is pointless, and a third will explain why we're doing everything wrong.

Here's the thing: we started this project because we wanted more people to have access to modern AI tools, safely. The script is free, open source, and works on any VPS from any provider. Yes, we sell pre-configured OpenClaw VPS for people who want a done-for-you option, but the script itself costs nothing and always will.

If you want to help, this is a win-win for everyone. The open source community gets a secure, maintained setup tool. Contributors get credited in all project documentation and on GitHub. We all benefit from more eyes on the security side.

If you think this is trash, feel free to scroll past. But if you have actual security expertise or development skills and want to make self-hosted AI safer for everyone, jump in. PRs, issues, code reviews, even just testing on your distro. Every contribution matters and every contributor gets recognized.


Thanked by 2mans_xd anakara

Comments

  • In the beginning of 2026, security researchers found 42,000+ OpenClaw instances running exposed to the internet with zero authentication. API keys, conversations, personal data, all wide open.

    let them be it

    Thanked by 2rarecloud forest
  • rarecloudrarecloud Member, Patron Provider

    @nghialele said:

    In the beginning of 2026, security researchers found 42,000+ OpenClaw instances running exposed to the internet with zero authentication. API keys, conversations, personal data, all wide open.

    let them be it

    :)))

  • mans_xdmans_xd Member

    last part is necessary for final boss gooner of LET

    Thanked by 1rarecloud
  • rarecloudrarecloud Member, Patron Provider

    @mans_xd said:
    last part is necessary for final boss gooner of LET

    lol :))

    Thanked by 1mans_xd
  • s0n1cs0n1c Member

    was this setup script made with openclaw?

    Thanked by 1rarecloud
  • rarecloudrarecloud Member, Patron Provider
    edited March 19

    @s0n1c said:
    was this setup script made with openclaw?

    Ahahaa:)))

    No, with Claude Code, lol :)

  • plumbergplumberg Veteran, Megathread Squad

    No AlmaLinux/ RHEL support...

    Sadage

    Thanked by 1rarecloud
  • Nvidia is going to release NemoClaw, based on OpenClaw, which will be very secure and ready for enterprise deployment.
    But, Kudos to the attempt !

    Thanked by 1rarecloud
  • uhh why we expose the openclaw to the internet? That is just an agent…

  • rarecloudrarecloud Member, Patron Provider

    @plumberg said:
    No AlmaLinux/ RHEL support...

    Sadage

    this is the reason we asked for contributors.

    Thanked by 1plumberg
  • rarecloudrarecloud Member, Patron Provider

    @FairShare said:
    Nvidia is going to release NemoClaw, based on OpenClaw, which will be very secure and ready for enterprise deployment.
    But, Kudos to the attempt !

    Yes, seen the news. too. It sounds good, waiting for the release.

  • forestforest Member

    @FairShare said: which will be very secure

    :#

  • rarecloudrarecloud Member, Patron Provider

    @forest said:

    @FairShare said: which will be very secure

    :#

    :)))

  • rarecloudrarecloud Member, Patron Provider
    edited April 3

    Hey everyone, bumping this thread with a quick update.


    First, sorry for not being more active here lately.
    We've been heads-down upgrading our infrastructure: building brand new servers with AMD Ryzen 7 5700G CPUs and NVMe storage for our Romania locations, which are almost ready. It's been consuming most of our time, but we haven't forgotten about this project.


    To the haters: totally fine if this isn't your thing, feel free to scroll past. We get it, LET is LET. But please keep it constructive if you do comment, there are people here who genuinely want to learn and contribute, and noise doesn't help anyone.


    To everyone else: we're still very much committed to making OpenClaw setup as easy, accessible, and secure as possible. The project is open source, free, and always will be. No catch.

    What you get if you contribute:

    • Permanent credit in the README (Contributors, Security Acknowledgments, or Sponsors section depending on your contribution)
    • Backlinks from the GitHub repo and our website, which has decent traffic
    • A public shoutout and free promotion: we will thank you publicly on LET, on all channels we post on, and mention you in our newsletters and emails to our subscriber and client base
    • The satisfaction of making self-hosted AI safer for thousands of people running exposed instances right now

    Where we need help right now:

    • AlmaLinux / RHEL support (highly requested!)
    • Security review and hardening suggestions
    • Testing on different environments
    • Documentation improvements

    - User experience improvements: making OpenClaw accessible to people who are not Linux experts, simpler setup flows, better error messages, guided configuration

    Repo: github.com/RareCloudio/openclaw-setup

    Even a small PR, an issue, or just testing it on your setup and reporting back counts. Every bit helps and every contributor gets recognized. Thanks.

  • Guru555Guru555 Member

    Do you expect others to develop a tool that you essentially use for self-promotion?

    Thanked by 1xvps
  • rarecloudrarecloud Member, Patron Provider

    @Guru555 said:
    Do you expect others to develop a tool that you essentially use for self-promotion?

    they will promote them-selves as well ... this is how open-source works

Sign In or Register to comment.