Run OpenClaw in Docker
Run the gateway and the CLI as Docker Compose services, built from source or pulled as the prebuilt ghcr.io/openclaw/openclaw image.
You need Git and Docker with Compose. Building the image locally takes at least 6 GB of RAM, so on a smaller host use the prebuilt image.
Clone the repository and run setup
The setup script in the repository prepares the Compose services. To skip the local build, export OPENCLAW_IMAGE=ghcr.io/openclaw/openclaw:latest before you run it. A mirror is also published on Docker Hub as openclaw/openclaw.
shell git clone https://github.com/openclaw/openclaw.git cd openclaw ./scripts/docker/setup.shOpen the dashboard
This runs the CLI container once for the dashboard command; --no-open stops it from trying to launch a browser inside the container. Other CLI commands work the same way, for example docker compose run --rm openclaw-cli channels add --channel telegram --token "<token>".
shell docker compose run --rm openclaw-cli dashboard --no-openPersist data and size the host
Keep the OpenClaw state, meaning openclaw.json and the agent workspace, on a named volume or bind mount so it survives container rebuilds and updates. Allow at least 6 GB of RAM if you build the image yourself; with the prebuilt image and cloud models, the gateway runs from 1 GB. Inside a container gateway.bind auto resolves to 0.0.0.0, so keep token auth on.
Update the containers
Pull new images for both the gateway and the CLI service, then recreate only the gateway. Your config and workspace stay on the volume.
shell docker compose pull openclaw-gateway openclaw-cli docker compose up -d openclaw-gateway
Because the gateway listens on 0.0.0.0 inside the container, a port mapping such as 18789:18789 publishes it on every host interface. Map it as 127.0.0.1:18789:18789 instead.