clawops provisions and operates self-hosted OpenClaw instances on AWS, GCP, Azure, or a Linux
machine you already have. It is one implementation behind two surfaces: a command-line tool, and
an MCP server that exposes the same operations to AI coding agents such as Claude Code and Cursor.
Deployments go through a plan you can read. clawops plan writes a JSON deploy plan — instance
type, region, firewall rules, OpenClaw version — and clawops apply executes exactly that.
Nothing is provisioned straight from a prompt, including when an agent is driving. Re-running is
idempotent, --dry-run previews, and a plan that would replace an instance says so first.
Day to day it handles what comes after the deploy: gateway status and health probes, log tailing,
a live monitor, reading and writing OpenClaw config with schema validation, agent listing, gateway
restart and version upgrades, backups, secret storage with rotation, SSH and port forwarding, and
a doctor command that checks prerequisites, credentials, SSH keys and configuration drift.
Hardening is built in and opt-in per module: deny-all firewall defaults, SSH hardening, UFW,
fail2ban, unattended upgrades and Docker socket permissions, plus per-cloud checks — AWS security
group audit, SSM, VPC flow logs and GuardDuty; GCP firewall audit, Shielded VM and OS Login;
Azure NSG audit, disk encryption, Defender and JIT access. A stack can be moved onto a Tailscale
network and its public ports closed entirely, with a verified route back.
The MCP server ships 20 typed tools with a read-only mode, a no-destructive mode, confirmation
prompts before destructive actions, and audit logging with secret redaction.
clawops uses your own cloud account and credentials, and never stores them. Windows is supported
through WSL2. TLS termination is not included, and restoring a backup verifies the archive and
expands it into a staging directory rather than activating it for you.
No comments or reviews, maybe you want to be first?