Openclaw Infra — Development skill for Claude Code
Secure self-hosted OpenClaw deployment on Hetzner Cloud with Tailscale.
How to install Openclaw Infra
This entry records only its repository, not the path inside it, so there is no
exact command to give. Open pandysp/openclaw-infra and copy the folder into
~/.claude/skills/, or the file into ~/.claude/agents/.
What Openclaw Infra does
Secure self-hosted OpenClaw deployment on Hetzner Cloud with Tailscale.
Alternatives in Development
- Microsandbox — Open-source self-hosted MicroVM sandboxes with sub-200ms startup, hardware-level isolation via libkrun 5k ★
- Harnessrouter — HarnessRouter Community Edition: the self-hosted, Apache-2.0 edition of the unified interface for agent harnes 618 ★
- AgentHandover — What if OpenClaw, Claude Code, Codex etc. knew how to do your work without you saying it 600 ★
README
OpenClaw Infrastructure
Self-hosted [OpenClaw](https://openclaw.ai) gateway on a Hetzner VPS with zero-trust Tailscale networking. No public ports exposed. ~€11.39/month.
**This is a reference template.** Clone it and adapt for your own deployment — the config values (timezone, model, cron prompts) are working examples you'll customize.
Features
- Cheap: Hetzner CX43 x86 (8 vCPU, 16 GB)
€9.49/mo + backups (€11.39/mo total) - Secure: Hetzner firewall + UFW + Tailscale-only access + device pairing
- Simple: Pulumi IaC, single command deploy, systemd user service
- Telegram: Optional scheduled tasks (configurable cron jobs)
- Workspace sync: Optional hourly git backup of the agent's workspace to GitHub
Prerequisites
- Node.js 18+
- Pulumi CLI
- Ansible (
pip install ansible) - Tailscale installed and connected on your machine
- Hetzner Cloud API token (console.hetzner.cloud)
- Tailscale auth key (login.tailscale.com/admin/settings/keys)
- Tailscale MagicDNS and HTTPS enabled (login.tailscale.com/admin/dns) — required for Tailscale Serve
- Claude setup token (run
claude setup-token)
See [CLAUDE.md](./CLAUDE.md#first-time-setup) for detailed setup instructions.
First-Time Tailscale Setup
If you've never used Tailscale before:
**Create account**: Go to https://tailscale.com/start
- Sign up with GitHub (recommended for infra projects), Google, or email
- Free tier supports up to 100 devices
**Install on your Mac**:
brew install --cask tailscale- Open Tailscale from Applications
- Click "Allow" for System Extension and VPN Configuration prompts
- Click menu bar icon → Log in → Authorize in browser
**Generate auth key for serv
Related Skills
Netclode
Self hosted cloud coding agent with k3s + kata containers + cloud hypervisor microVMs + tailscale + any harnes
Openclaw Secure Stack
🔒 One-command secure OpenClaw deployment with built-in skills scanner and prompt injection protection
Yantra
Name the work, not the machine. A self-hosted control plane for ssh, tmux and coding agents across your own ma
ServerFS MCP
Secure self-hosted MCP server exposing selected Linux directories as controlled workdirs via OpenAI Secure MCP
Open Agenthub
A home for your coding agent. Claude Code shouldn't stop when your laptop sleeps — Open AgentHub gives your ag
Terminal Handoff
Persistent Claude Code session handoff and secure remote control from authorised devices, with automatic conti
Related Agents
Infra Mesh
Mesh network specialist. Peer enrollment, groups, routes, policies, setup keys, and management-plane diagnosti
GitHub Actions Engineer
GitHub Actions CI/CD engineer: reusable workflows and composite actions, supply-chain hardening, caching and m
Squad DevOps
Operate as the squad's DevOps Engineer — containers, CI/CD, IaC, cloud and self-hosted delivery, proxies and T