OpenClaw, in its own sandbox
Give OpenClaw a machine to act on, not your laptop.
It runs around the clock in a sandbox of its own: a workspace, which is a
separate account on your server with its own files and logins, no sudo,
and no way into your other workspaces. Whatever the agent installs, or
breaks, stays inside it.
You need: a VPS (tested on Debian and Ubuntu).
Before you start: machine, skills, workspace
curl -fsSL https://mydevmachine.sh/install.sh | sh
devmachine setup
devmachine skills add
devmachine workspaces new agent
devmachine sync
Already have a machine? Skip setup. Already have the workspace? Skip the
last two. See getting started for what each command
does.
By hand
1. Install OpenClaw
devmachine ssh agent
curl -fsSL https://openclaw.ai/install.sh | bash
The installer sets up Node itself if the account has none. A workspace is
its own account, so this never touches acme or any other workspace — see
machines and workspaces.
2. Keep it running
openclaw onboard
openclaw onboard walks through first-time setup, then runs the Gateway in
the foreground. You do not need to start tmux: the login is already in
tmux, and it stays alive after you log out. Detach with Ctrl-b d, or just
close the terminal. To make it survive a reboot too, see OpenClaw’s own docs
on running it as a background service (openclaw onboard --install-daemon).
With your agent
Open a session on your own computer (devmachine skills add taught it the
CLI) and say:
Create a devmachine workspace called agent and install OpenClaw in it.
The agent creates the workspace, runs sync, then installs OpenClaw over
SSH and starts openclaw onboard. You still approve sync when it asks,
and OpenClaw’s own onboarding — any account or key it asks for — is yours to
answer.
Check it: devmachine ssh agent again. You land back in the same
session, and the Gateway is still running.
Source: OpenClaw — Install
Where to go next
- Agents
Hermes Agent, in its own sandbox
Run Nous Research's Hermes Agent always on, in a sandbox of its own.
Beginner
- Workspaces
One consultant, three startups
One server, one sandbox per client: separate stacks, logins and agents that never mix.
Intermediate
- Workspaces
Keep your sessions running
Close the laptop, and Claude Code keeps working on the server inside tmux.
Beginner