惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

WordPress大学
WordPress大学
N
News | PayPal Newsroom
雷峰网
雷峰网
Y
Y Combinator Blog
博客园 - 【当耐特】
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
B
Blog
Blog — PlanetScale
Blog — PlanetScale
F
Fortinet All Blogs
云风的 BLOG
云风的 BLOG
Microsoft Azure Blog
Microsoft Azure Blog
CTFtime.org: upcoming CTF events
CTFtime.org: upcoming CTF events
U
Unit 42
The Cloudflare Blog
The GitHub Blog
The GitHub Blog
Recorded Future
Recorded Future
Vercel News
Vercel News
N
Netflix TechBlog - Medium
GbyAI
GbyAI
博客园 - 司徒正美
美团技术团队
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
J
Java Code Geeks
P
Proofpoint News Feed
I
InfoQ
IT之家
IT之家
F
Full Disclosure
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
Google DeepMind News
Google DeepMind News
Apple Machine Learning Research
Apple Machine Learning Research
Forbes - Security
Forbes - Security
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
C
Cyber Attacks, Cyber Crime and Cyber Security
The Last Watchdog
The Last Watchdog
月光博客
月光博客
W
WeLiveSecurity
S
Securelist
Schneier on Security
Schneier on Security
Help Net Security
Help Net Security
T
Threat Research - Cisco Blogs
D
DataBreaches.Net
P
Privacy & Cybersecurity Law Blog
L
LINUX DO - 最新话题
K
KPMG report finds enterprise disconnect between AI and its ROI | CIO
Scott Helme
Scott Helme
D
Darknet – Hacking Tools, Hacker News & Cyber Security
K
Kaspersky official blog
Hacker News - Newest:
Hacker News - Newest: "LLM"
博客园 - Franky
cs.AI updates on arXiv.org
cs.AI updates on arXiv.org

DEV Community

Authentication Security Deep Dive: From Brute Force to Salted Hashing (With Java Examples) Why AI Systems Don’t Fail — They Drift Spilling beans for how i learn for exam😁"Reinforcement Learning Cheat Sheet" I Replaced Chrome with Safari for AI Browser Automation. Here's What Broke (and What Finally Worked) How Python Borrows Other People's Work The $40 Architecture: Processing 1 Billion API Requests with 99.99% Uptime Vibe Coding: A Workflow Guide (From Zero to SaaS) Most webhook security guides protect the wrong side. The scary part is delivery. Headless CMS for TanStack Start: Build a Blog with Cosmic EU Age Verification App "Hacked in 2 Minutes" — What Actually Happened Comfy Cloud’s delete function does not actually remove files Running AI Models on GPU Cloud Servers: A Beginner Guide Event-driven media intelligence with AWS Step Functions and Bedrock I scored 500 AI prompts across 8 quality dimensions — here's what broke How to Call Google Gemini API from Next.js (Free Tier, No Backend Needed) The Portal Protocol: Reclaiming Human Connection in the Age of AI How to Fix Your Team's Scattered Knowledge Problem With a Self-Hosted Forum Intro to tc Cloud Functors: A Graph-First Mental Model for the Modern Cloud Designing Multi-Tenant Backends With Both Ownership and Team Access I Built a Neumorphic CSS Library with 77+ Components — Here's What I Learned PostgreSQL Performance Optimization: Why Connection Pooling Is Critical at Scale Cómo construí un SaaS multi-rubro para gestionar expensas en Argentina con FastAPI + Vue 3 🚀 I Built an Ethical Hacking Scanner Tool – Open Source Project I Replaced /usage and /context in Claude Code With a Single Statusline A Pythonic Way to Handle Emails (IMAP/SMTP) with Auto-Discovery and AI-Ready Design I Collected 8.9 Million Polymarket Price Points — Here's What I Found About How Markets Really Move EcoTrack AI — Carbon Footprint Tracker & Dashboard Everyone's Using AI. No One Agrees How. 5 self-hosted ebook managers worth trying in 2026 Building Your First AI Agent with LangChain: From Chatbot to Autonomous Assistant Common SOC 2 Failures (Real World) Stop Vibe-Checking Your AI App: A Practical Guide to Evals How to Use SonarQube and SonarScanner Locally to Level Up Your Code Quality Your Next To-Do App Is Dead — I Replaced Mine with an OpenClaw AI Sign a Nostr event in 60 lines of Python using coincurve — no nostr-sdk, no nbxplorer, no rust toolchain ITGC Audit Explained Like You’re in Big 4 Patch Tuesday abril 2026: Microsoft parcha 163 vulnerabilidades y un zero-day en SharePoint Stop scraping everything: a better way to track competitor price changes Listing on MCPize + the Official MCP Registry while routing payments OUTSIDE the marketplace — how I kept 100% of my x402 revenue Building an AI-Powered Risk Intelligence System Using Serverless Architecture Why We Ripped Function Overloading Out of Our AI Toolchain Testing AI-Generated Code: How to Actually Know If It Works SaaS Churn Is Killing Your Business. Here Is What to Do About It (Without a Support Team) The Speed of AI Is No Longer Linear - And Self-Improving Models Are Why How to Implement RBAC for MCP Tools: A Practical Guide for Engineering Teams From Standard Quote to Persuasive Proposal: AI Automation for Arborists I built a CLI that scaffolds complete multi-tenant SaaS apps Axios CVE-2025–62718: The Silent SSRF Bug That Could Be Hiding in Your Node.js App Right Now The dashboard that ended our friendship Data Pipelines Explained Simply (and How to Build Them with Python) The Hidden Cost of AI Systems Nobody Talks About. undefined vs undeclared, and how typeof behaves Switching from file-based jobs to NATS/Kafka in Rust without changing code io_uring Adventures: Rust Servers That Love Syscalls Why Agentic AI is Killing the Traditional Database The POUR principles of web accessibility for developers and designers Quantum Neural Network 3D — A Deep Dive into Interactive WebGL Visualization How To Install Caveman In Codex On macOS And Windows Automation Pipeline Reliability: Why Your Workflow Breaks When Nobody Is Watching I Built an 'Open World' AI Coding Agent — It Works From ANY Folder From Freelancing to Product: A Tech Service Company's SaaS Transformation China's AI Giants: Adding Tencent Hunyuan & ByteDance Doubao to AI University (74 Providers) On the Vibe Coders and Their Lies clerk: Auto-Summarize Your Claude Code Sessions AI Weekly — 2026/04/10–04/17 | The Model Lockdown Is Here, but the Toolchain Is the Real Battleground AI 週報 — 2026/04/10–2026/04/17 模型封鎖潮來了,但工具鏈才是真戰場 Maybe this is how Open-Source apps are born... 🚀 Fine-Tune LLMs with LoRA and QLoRA: 2026 Guide tRPC v11 + Next.js App Router: End-to-End Type Safety Without the Boilerplate ShadCN UI in 2026: Why I Stopped Installing Component Libraries and Started Owning My Components SaaS Billing in React Server Components: Stripe + Supabase Without a Single `useEffect` Join our DEV Weekend Challenge — $1,000 in Prizes Across TEN winners! Submissions Due April 20 at 6:59 AM UTC. Implementing FSRS Spaced Repetition in Flutter + Supabase — Adding Memory Science to an AI Learning App "I Texted My Localhost From the Train — Claude Code Fixed the Bug Before I Got Home" I Built a Sales Prep AI and It Went Deeper Than Expected Design to Code #2: One JSON, Eleven Outputs Solving the 100M-Row Problem: A Summary Table Pattern for High-Volume Push Notification Logs Flutter Web With Wasm: What Actually Changes For Developers I Built 50 Royalty-Free Soundtracks for My Side Project in a Weekend Using AI Music Generation The Vibe Coding Security Checklist: 7 Things to Check Before You Ship Stop Letting Googlebot Guess Fix Your React App's SEO Right Desconstruindo o Streaming do LinkedIn: Como Criar um Engine de Extração de Vídeo de Alta Performance com HLS e FFmpeg (EDA Part-1) EDA (Exploratory Data Analysis) Explained With Real Life — Why Looking at Your Data Is the Most Important Step in Machine Learning Brand Relationship Management at Scale: Our 4-Touch Outreach System for 200+ Brands Why String.fromEnvironment() Might Return an Empty String in Dart JGuardrails 1.0.0 — Hardening Java LLM Apps Against Jailbreaks, Toxicity, and Prompt Injection Plan and Schedule a Full Week of Threads Content From One Claude Conversation Coding Cat Oran Ep3, Five Tables Changed Everything Updated: BFF Pattern I'm done watching freelancers get buried by 200 proposals. So I'm building the alternative. This is my first post BFS Algorithm in Java Step by Step Tutorial with Examples Tracking LLM Pricing Monthly: An Open Dataset for 22 AI Models How We Measure Content ROI on a Comparison Site: Revenue Attribution Without Perfect Data Introducing Nova AI Ops: The AI-Native Operating System for SRE Teams I built a free desktop video downloader for Windows — Grabbit How Talkie OCR Helps Vision-Impaired & Dyslexic Users Read the World Around Them VRCFaceTracking安装和iPhone面捕配置教程,有bug Even CrowdStrike Can't See Your Agents The Automation Gold Rush: What n8n Workflows and Claude Are Opening Up for Developers Right Now
Installing OpenClaw on Linux - 0$ Personal Agentic AI Assistant - Part 4
AK DevCraft · 2026-06-01 · via DEV Community

Introduction

Part 4 of the Zero Dollar AI Assistant series- Installing OpenClaw on Linux — Avoiding Every Trap. Part 1 covers the architecture. Part 2 covers Oracle Cloud setup. Part 3 covers Ollama and model selection.

OpenClaw's documentation assumes a Mac. The install script works on Linux, but several things that work automatically on Mac require manual intervention on a Linux server. This article documents every one of them, the right user to install as, the systemd service traps, the config file quirks, and the silent background token drain that will surprise you on day one.

Install as the Right User

This sounds trivial. It isn't.

The OpenClaw installer sets up a systemd user service, a service that runs under a specific user account, not as root. If you install as root, the systemd user service won't work correctly, the gateway won't auto-start on boot, and you'll spend time debugging problems that don't exist on a proper install.

Always install as a non-root user. On Oracle Cloud, that user is ubuntu.

Verify before installing:

whoami
# Must show: ubuntu

If you're currently root, exit and SSH back in directly as ubuntu:

exit  # if su'd to root
ssh -i ~/.ssh/id_rsa ubuntu@YOUR_PUBLIC_IP

Switching via su - ubuntu from a root session isn't sufficient; the systemd user session won't be properly initialized, and you'll get "systemd user services unavailable" errors during setup.

Installation

# use tmux — install may take several minutes
tmux new -s openclaw
curl -fsSL https://openclaw.ai/install.sh | bash

The installer will launch the onboarding wizard automatically on completion.

The Onboarding Wizard

Work through each step. Key selections for this stack:

  • AI Provider: Ollama

  • Ollama host: http://localhost:11434

  • Model: Select ollama/llama3.2:3b from the browse list — look for the entry showing (ctx 128K)

  • Search provider: Skip for now — or select a provider if you have a key. Tavily has a free tier at tavily.com.

  • Secret provider: No, secrets stored in openclaw.json directly is fine for a personal server

  • Skills: Skip all for now. Add after verifying the core setup works. One gotcha: the GitHub skill tries to install via Homebrew, which doesn't exist on Linux; skip it here and install the GitHub CLI via apt afterward.

  • Hooks: Skip

  • Hatch: Select "Hatch in terminal". This verifies that the gateway starts correctly before you exit the wizard

⚠️ On first hatch, OpenClaw reads BOOTSTRAP.md from the workspace and prompts you to have a setup conversation with the agent to define its identity and personality. This is intentional — but with a local 3B model, it's very slow. Skip it by creating the files manually (covered below).

Skip the Bootstrap Conversation

The bootstrap flow is designed for interactive use; it has a conversation with you to set the agent's name, personality, and preferences. With a local 3B model, this takes 10-15 minutes of slow back-and-forth.

Create the required files manually instead:

# Create SOUL.md - agent personality and preferences
cat > ~/.openclaw/workspace/SOUL.md << 'EOF'
# Soul

## Identity
- Name: Claw
- Vibe: Casual, helpful, direct
- Emoji: 🦞

## User
- Preferred responses: Concise, no fluff
- Direct answers preferred

## Preferences
- Keep responses brief
- No unnecessary preamble
EOF

# Create IDENTITY.md
cat > ~/.openclaw/workspace/IDENTITY.md << 'EOF'
# Identity
- Name: Claw
- Nature: AI assistant
- Vibe: Casual and helpful
- Emoji: 🦞
EOF

# Create USER.md
cat > ~/.openclaw/workspace/USER.md << 'EOF'
# User
- Name: Your name here
- Preferred address: Your name
EOF

# Delete the bootstrap file to clear the pending state
rm ~/.openclaw/workspace/BOOTSTRAP.md

Customise the files with your actual name and preferences. Once BOOTSTRAP.md is deleted, the gateway proceeds normally.

Post-Install Configuration

We don’t have to configure all the settings during onboarding; we can pick and configure as we go. That way, we don’t have to worry about having all the information that is needed, like api key or bot token, during onboarding.

1. Create a Telegram Bot and Configure the Channel

Create your bot via BotFather:

  1. Open Telegram → search @botfather
  2. Send /newbot
  3. Choose a display name (e.g., My AI Assistant)
  4. Choose a username — must end in bot (e.g., myassistant_bot)
  5. BotFather replies with your token: 12346789:AAFxxx... — save this

Add the channel to OpenClaw via the wizard:

openclaw channels add

The wizard walks you through selecting Telegram, entering your bot token, and setting access policies. A few things to watch for during setup:

  • When asked about a secret provider — select No
  • When asked about DM access policy — select pairing (only your approved accounts can talk to the agent)
  • When asked to bind accounts to agents — select Yes

⚠️ The wizard may ask to install the Telegram plugin from npm — this may fail. Telegram is a bundled plugin. If you see this error, run openclaw plugins enable telegram first, then retry openclaw channels add.

2. Add Gemini Fallback

Add the Gemini API key you obtained in Part 3 to the systemd service:

sed -i '/Environment=OPENCLAW_SERVICE_KIND=gateway/a Environment=GEMINI_API_KEY=your_gemini_key_here' \
  ~/.config/systemd/user/openclaw-gateway.service

Configure Ollama as primary with Gemini as fallback:

openclaw config set agents.defaults.model.primary "ollama/llama3.2:3b"
openclaw config set agents.defaults.model.fallbacks '["gemini/gemini-2.5-flash-lite"]' --json

# Add available model list
openclaw config set agents.defaults.models '{"ollama/llama3.2:1b": {}, "google/gemini-2.5-flash-lite": {}}' --json

3. Enable Ollama Auto-Discovery

This tells OpenClaw to automatically detect all locally running Ollama models:

echo 'export OLLAMA_API_KEY=ollama-local' >> ~/.bashrc
source ~/.bashrc

sed -i '/Environment=OPENCLAW_SERVICE_KIND=gateway/a Environment=OLLAMA_API_KEY=ollama-local' \
  ~/.config/systemd/user/openclaw-gateway.service

4. Disable mDNS

Oracle Cloud doesn't support mDNS/Bonjour, leaving it enabled causes repeated crash-restart cycles:

openclaw gateway stop
openclaw config set discovery.mdns.mode off
openclaw config set discovery.wideArea.enabled false

5. Apply Low-Power Optimizations

These reduce startup time and memory overhead:

mkdir -p /var/tmp/openclaw-compile-cache
echo 'export NODE_COMPILE_CACHE=/var/tmp/openclaw-compile-cache' >> ~/.bashrc
echo 'export OPENCLAW_NO_RESPAWN=1' >> ~/.bashrc

sed -i '/Environment=OLLAMA_API_KEY/a Environment=NODE_COMPILE_CACHE=/var/tmp/openclaw-compile-cache' \
  ~/.config/systemd/user/openclaw-gateway.service
sed -i '/Environment=NODE_COMPILE_CACHE/a Environment=OPENCLAW_NO_RESPAWN=1' \
  ~/.config/systemd/user/openclaw-gateway.service

source ~/.bashrc

6. Add Gateway Token to CLI

The CLI needs the gateway token to authenticate against the running service:

# Get your token
python3 -c "import json; import os;d=json.load(open(os.path.expanduser('~/.openclaw/openclaw.json'))); print(d['gateway']['auth']['token'])"

# Add to bashrc
echo 'export OPENCLAW_TOKEN=your_token_here' >> ~/.bashrc
source ~/.bashrc

7. Reload and Restart

systemctl --user daemon-reload
openclaw gateway start

The Silent Token Drain

This is the most important thing in this article.

OpenClaw has a background process that runs every 30 minutes — sweepStaleRunContexts which cleans up expired agent sessions. On a fresh install with default settings, this sweep triggers a Claude API call each time it runs via the startupContext feature, which loads daily memory on every session reset.

The result: if you're using the Anthropic API (not Ollama), you'll see API calls every 30 minutes even when nobody is using the assistant. Left overnight, this consumed $2-3 in API credits silently.

Disable startup context to prevent this:

openclaw gateway stop
openclaw config set agents.defaults.contextInjection.startupContext.enabled false
openclaw gateway start

ℹ️ If you're using Ollama as your primary model with Gemini as a fallback (as set up in this series), this is less of a concern — the sweep uses your local model at zero cost. But if you ever switch to an Anthropic API key as primary, disable this first.

Verifying the Installation

  • 1. Check gateway status:
openclaw gateway status

A healthy output shows:

Connectivity probe: ok
Capability: read-only
Runtime: running

  • 2. Check if the Ollama model has been discovered:
openclaw models list

Should show ollama/llama3.2:3b as configured.

  • 3. Check logs in real time:
openclaw logs --follow

# You can update logging level as below
openclaw config set logging.level "info"


Common Issues

  • systemd user services unavailable
    You installed as root or switched via su. Exit completely and SSH back in directly as the ubuntu user. A proper login session is required for systemd user services.

  • Gateway starts, but Telegram is not connecting
    The bot token isn't in the config, or the IPv6 issue is causing timeouts. Verify:

grep -i telegram ~/.openclaw/openclaw.json
curl -4 https://api.telegram.org/botYOUR_TOKEN/getMe

  • CIAO PROBING CANCELLED crash
    mDNS is not disabled. Follow step 4 in the post-install configuration above.

  • Config changes disappear after gateway restart
    The gateway rewrites openclaw.json on startup. Always stop the gateway before editing the config:

openclaw gateway stop
# make edits
openclaw gateway start

  • Model times out in agent mode but works in ollama run
    OpenClaw's agent mode adds tool context, memory, and session history to every request — significantly heavier than a bare model call. Switch to llama3.2:3b if using a larger model, or add Gemini as a fallback to catch timeouts.

  • HTTP 401 on CLI commands
    The OPENCLAW_TOKEN environment variable isn't set. Add it to ~/.bashrc (see step 6 above).

What's Next

Gateway running, Telegram configured, Ollama as primary, Gemini as fallback — all the pieces are in place.

Part 5 and the final part cover pairing your Telegram account, testing the end-to-end flow, and making the whole setup production-ready for daily use.

This article is the fourth in a five-part series:

  1. $0 Personal Agentic AI Assistant - Architecture
  2. Setting Up Free Cloud Server — VCN, ARM instances, static IPs, the gotchas
  3. Running Ollama on ARM — model selection, disk management, CPU inference, reality
  4. Installing OpenClaw on Linux — avoiding every trap ← you are here
  5. The Complete Setup — Telegram, end-to-end testing

Stay tuned, all links will be updated as articles are published.

If you have reached this point, I have made a satisfactory effort to keep you reading. Please be kind enough to leave any comments or share any corrections.


My Other Blogs: