The Problem
You run OpenClaw on a home server or VPS. You want to reach it from your laptop, phone, or another machine — without exposing port 18789 to the internet.
Tailscale solves this. It creates an encrypted mesh network between your devices. No port forwarding, no dynamic DNS, no firewall holes.
Install Tailscale
On the machine running OpenClaw:
curl -fsSL https://tailscale.com/install.sh | sh
sudo tailscale upNote your Tailscale IP:
tailscale ip -4
# Example: 100.64.0.5Configure OpenClaw
Set the bind mode to tailnet:
openclaw config set gateway.bind tailnet
openclaw config set gateway.controlui.allowedOrigins '["http://100.64.0.5:18789"]'
openclaw gateway restartOr use the Tailscale hostname:
openclaw config set gateway.controlui.allowedOrigins '["http://my-server.tail12345.ts.net:18789"]'
openclaw gateway restartMaster this topic with hands-on labs
Go beyond reading — build real projects in sandboxed environments with expert video guidance.
Browse Courses →Access from Any Device
From any device on your tailnet, open:
http://my-server.tail12345.ts.net:18789Enter your gateway token when prompted. Works from your phone, laptop, or any other Tailscale-connected device.
Docker + Tailscale
If OpenClaw runs in Docker, Tailscale runs on the host. Bind to 0.0.0.0 and let Tailscale handle access control:
services:
openclaw:
image: openclaw/openclaw:latest
ports:
- "18789:18789"
environment:
- OPENCLAW_GATEWAY_BIND=0.0.0.0
- OPENCLAW_GATEWAY_CONTROLUI_ALLOWEDORIGINS=["http://100.64.0.5:18789"]
volumes:
- openclaw-data:/home/node/.openclawThen use Tailscale ACLs to restrict which devices can reach port 18789.
Tailscale ACLs
Lock down access in your Tailscale admin console:
{
"acls": [
{
"action": "accept",
"src": ["tag:admin"],
"dst": ["tag:openclaw:18789"]
}
]
}Only devices tagged admin can reach your OpenClaw instance.
Get weekly IT automation tips
Docker, Ansible, Terraform, MLOps — curated insights delivered to your inbox. No spam.
Subscribe Free →HTTPS with Tailscale
Tailscale can provision HTTPS certificates for your tailnet hostnames:
tailscale cert my-server.tail12345.ts.netThen point Caddy at the certs or use tailscale serve:
tailscale serve --bg https+insecure://localhost:18789Now you have HTTPS at https://my-server.tail12345.ts.net with zero configuration.
Why Not Just Use a VPN?
Traditional VPNs route all traffic through a single gateway. Tailscale creates direct connections between devices. Your OpenClaw traffic goes directly from your phone to your server — no hub bottleneck.
Related Posts
- Deploy OpenClaw with Docker Compose for the base setup
- OpenClaw Reverse Proxy with Caddy for domain-based HTTPS
- OpenClaw Gateway Bind Modes for all binding options
---
Ready to go deeper? Check out our hands-on course: OpenClaw Agent — practical exercises you can follow along on your own machine.
Related
For a production-focused walkthrough, see Luca Berton's guide on OpenClaw-driven CVE remediation with Ansible.
Ready to learn by doing?
Stop reading tutorials — start building. Expert video courses with hands-on labs in real sandboxed environments.
Related Articles
OpenClaw Volume Permissions Fix
Fix OpenClaw Docker volume permission errors. Resolve EACCES issues for named volumes and bind mounts with troubleshooting steps.
Troubleshoot OpenClaw Gateway Errors
Fix OpenClaw gateway errors: 401 unauthorized, connection refused, origin not allowed, and WebSocket failures with resolution guides.
OpenClaw Reverse Proxy with Caddy
Set up HTTPS for OpenClaw using Caddy reverse proxy. Automatic TLS certificates, WebSocket support, and production config.
OpenClaw + Telegram Bot
Connect your OpenClaw agent to Telegram for a personal AI assistant accessible from your phone. Setup guide with BotFather and configuration.
OpenClaw vs ChatGPT
Compare OpenClaw's self-hosted approach with ChatGPT and other cloud AI services. Learn the trade-offs between control, privacy, and convenience.
OpenClaw vs LangChain vs AutoGPT
Compare OpenClaw with LangChain, AutoGPT, and other AI agent frameworks. Understand the differences in architecture, use cases, and philosophy.
Explore topics
Browse more articles on the topics covered here.