OpenClaw AWS Deploy for Openclaw

A robust automation skill to deploy, manage, and tear down secure OpenClaw agent instances on AWS infrastructure.

godwinbabu
v1.0.0
Feb 18, 2026
0
1.4k
0

Install & Download

1. ClawHub CLI

The fastest way to install a skill directly from the registry.

npx clawhub@latest install openclaw-aws-deploy

2. Manual Installation

Copy the skill folder to one of these locations

Global
~/.openclaw/skills/
Workspace
<project>/skills/

Priority: Workspace > Local > Bundled

3. Prompt Installation

Copy this prompt to OpenClaw to install it automatically.

Help me install openclaw-aws-deploy using Clawhub. If Clawhub is not installed, install it first (npm i -g clawhub).

Prefer to download?

Get the raw skill files in a ZIP archive.

What is OpenClaw AWS Deploy?

This skill provides a streamlined, production-ready pathway to hosting OpenClaw agents on AWS. It automates the creation of a hardened VPC, IAM roles with least-privilege permissions, and ARM64-based EC2 instances optimized for price and performance. By leveraging AWS Systems Manager (SSM) instead of SSH, it ensures a zero-inbound-port security posture while maintaining full developer access.

The OpenClaw AWS Deploy skill is designed for developers who need reliable, scalable, and secure environments for their AI agents. It handles the complexities of Node.js 22 installation, secret management via AWS SSM Parameter Store, and seamless integration with AI models from AWS Bedrock and Google Gemini, making it a cornerstone for professional Openclaw Skills deployments.

OpenClaw AWS Deploy Use Cases

  • Setting up a fresh OpenClaw instance on AWS for production use.
  • Deploying temporary agent environments for testing specific AI models like DeepSeek or Gemini.
  • Automating the scaling of AI agent infrastructure using CI/CD pipelines.
  • Rapidly tearing down AWS resources to minimize costs when agents are not in use.

How OpenClaw AWS Deploy Works

  1. The script initializes the network layer by creating a dedicated VPC, public subnet, and Internet Gateway.
  2. It configures IAM roles with specific permissions for SSM Session Manager, Parameter Store, and AWS Bedrock.
  3. Secrets from local environment files are securely uploaded to AWS SSM Parameter Store to prevent exposure in code.
  4. A t4g.medium ARM64 instance is launched with a customized bootstrap script in the user-data field.
  5. The instance automatically installs Node.js 22, configures OpenClaw, and fetches runtime secrets.
  6. A smoke test is performed via SSM to verify the agent is live and properly connected to the Telegram communication channel.

OpenClaw AWS Deploy Setup

Ensure you have the aws CLI, jq, and openssl installed. Configure your .env.starfish with the required TELEGRAM_BOT_TOKEN before starting.

# Deploy a minimal instance with a single command
./scripts/deploy_minimal.sh --name starfish --region us-east-1 --env-dir /path/to/workspace

# Approve the Telegram pairing via SSM session
aws ssm start-session --target <INSTANCE_ID> --region us-east-1
sudo -u openclaw openclaw pairing approve telegram <YOUR_CODE>

OpenClaw AWS Deploy Data Schema & Taxonomy

The skill manages infrastructure and agent state using a structured metadata approach to ensure clean lifecycle management within Openclaw Skills.

Data Object Format Description
deploy-output.json JSON Contains all AWS Resource IDs for the specific deployment to enable easy teardown.
openclaw.json JSON The main runtime configuration, specifying model providers and plugin settings.
auth-profiles.json JSON Stores authentication metadata for external providers like Google Gemini.
SSM Parameters AWS Secret Secure storage for bot tokens and API keys, fetched only at service runtime.

OpenClaw AWS Deploy Advanced Features

  • Multi-model flexibility: Easily switch between AWS Bedrock and Gemini via simple CLI flags during deployment.
  • Deterministic Teardown: Cleanly remove all associated AWS resources using the generated output file to prevent cloud waste.
  • Hardened Security: Enforces IMDSv2, encrypted EBS volumes, and zero inbound firewall rules for maximum protection.
  • Optimized Performance: Leverages ARM64 (Graviton) architecture for superior price-to-performance ratios for your Openclaw Skills.
  • Ephemeral Configs: Startup scripts rewrite config files on every service start, ensuring secrets are never stored in static images.

SKILL.md


Loading

Related Openclaw Skills

METADATA

Github Stars: 0
forks: 0

Featured*