跳转至

exe.dev

目标: 在 exe.dev 虚拟机上运行 OpenClaw Gateway,并通过 https://<vm-name>.exe.xyz 访问。

本指南假定使用 exe.dev 默认的 exeuntu 镜像。在其他发行版上请酌情调整软件包。

需要准备什么

  • exe.dev 账号
  • 可访问 exe.dev 虚拟机的 ssh exe.dev(可选,用于手动安装)

新手指南快速路径

  1. 打开 https://exe.new/openclaw
  2. 根据需要填写你的认证密钥/令牌
  3. 点击虚拟机旁边的“Agent”,等待 Shelley 完成预配置
  4. 打开 https://<vm-name>.exe.xyz/,使用配置的共享密钥进行认证(默认使用令牌认证;如果你切换了 gateway.auth.mode,密码认证也可以)
  5. 使用 openclaw devices approve <requestId> 批准待处理的设备配对请求

使用 Shelley 自动安装

exe.dev 的 agent Shelley 可以通过一条提示词来安装 OpenClaw:

Set up OpenClaw (https://docs.openclaw.ai/install) on this VM. Use the non-interactive and accept-risk flags for openclaw onboarding. Add the supplied auth or token as needed. Configure nginx to forward from the default port 18789 to the root location on the default enabled site config, making sure to enable Websocket support. Set gateway.controlUi.allowedOrigins to the exact https://<vm-name>.exe.xyz origin, and set gateway.trustedProxies to ["127.0.0.1"] because nginx connects to the Gateway over loopback and overwrites X-Forwarded-For. Pairing is done by "openclaw devices list" and "openclaw devices approve <request id>". Make sure the dashboard shows that OpenClaw's health is OK. exe.dev handles forwarding from port 8000 to port 80/443 and HTTPS for us, so the final "reachable" should be <vm-name>.exe.xyz, without port specification.

手动安装

1. 创建 VM

在本地设备上执行:

```bash
ssh exe.dev new
```

然后连接:

```bash
ssh <vm-name>.exe.xyz
```

Tip

请保持此 VM 为有状态。OpenClaw 会将 openclaw.json、共享和按 agent 划分的 SQLite 认证存储、会话、渠道/提供商状态存储在 ~/.openclaw/ 下,工作区则存储在 ~/.openclaw/workspace/ 下。

2. 安装前置依赖(在 VM 上)

sudo apt-get update
sudo apt-get install -y git curl jq ca-certificates openssl

3. 安装 OpenClaw

curl -fsSL https://openclaw.ai/install.sh | bash

4. 配置 nginx 以代理到端口 8000

编辑 /etc/nginx/sites-enabled/default:

server {
    listen 80 default_server;
    listen [::]:80 default_server;
    listen 8000;
    listen [::]:8000;

    server_name _;

    location / {
        proxy_pass http://127.0.0.1:18789;
        proxy_http_version 1.1;

        # WebSocket support
        proxy_set_header Upgrade $http_upgrade;
        proxy_set_header Connection "upgrade";

        # Standard proxy headers
        proxy_set_header Host $host;
        proxy_set_header X-Real-IP $remote_addr;
        proxy_set_header X-Forwarded-For $remote_addr;
        proxy_set_header X-Forwarded-Proto $scheme;

        # Timeout settings for long-lived connections
        proxy_read_timeout 86400s;
        proxy_send_timeout 86400s;
    }
}

覆盖转发头,而不是保留客户端提供的链。OpenClaw 只信任来自显式配置代理的转发 IP 元数据,并且追加式的 X-Forwarded-For 链被视为加固风险。

5. 信任 nginx 并允许公开浏览器来源

配置准确的公开来源,并且只信任回环 nginx 这一个跳点:

openclaw config set gateway.controlUi.allowedOrigins '["https://<vm-name>.exe.xyz"]' --strict-json
openclaw config set gateway.trustedProxies '["127.0.0.1"]' --strict-json
openclaw gateway restart

浏览器来源检查对于公开主机名是失败即关闭的。代理白名单让 OpenClaw 使用 nginx 覆盖后的 X-Forwarded-For 值,而不是把每个请求都视为来自回环代理。请将此列表限制为你控制的代理。

6. 访问 OpenClaw 并批准设备

打开 https://<vm-name>.exe.xyz/(参见 onboarding 输出的 Control UI)。如果提示认证,请粘贴 VM 上配置的共享密钥。

本指南默认使用令牌认证,因此在交互终端中运行 openclaw gateway auth-token --show 可以获取已配置的令牌。如果尚未配置令牌,可使用 openclaw doctor --generate-gateway-token 生成一个并重启 Gateway。如果你已将 gateway 切换为密码认证,请改用 gateway.auth.password / OPENCLAW_GATEWAY_PASSWORD。

使用 openclaw devices list 和 openclaw devices approve <requestId> 批准设备。如有疑问,可直接在浏览器中使用 Shelley。

远程渠道设置

对于远程主机,优先使用一次 config patch 调用,而不是多次通过 SSH 调用 config set。将真实令牌保存在 VM 环境或 ~/.openclaw/.env 中,并且只在 openclaw.json 中放入 SecretRef。完整的 SecretRef 契约请参阅 Secrets 管理。

在 VM 上,让服务环境包含所需密钥:

cat >> ~/.openclaw/.env <<'EOF'
SLACK_BOT_TOKEN=xoxb-...
SLACK_APP_TOKEN=xapp-...
DISCORD_BOT_TOKEN=...
OPENAI_API_KEY=sk-...
EOF

在本地机器上创建补丁文件并通过管道发送到 VM:

// openclaw.remote.patch.json5
{
  secrets: {
    providers: {
      default: { source: "env" },
    },
  },
  channels: {
    slack: {
      enabled: true,
      mode: "socket",
      botToken: { source: "env", provider: "default", id: "SLACK_BOT_TOKEN" },
      appToken: { source: "env", provider: "default", id: "SLACK_APP_TOKEN" },
      groupPolicy: "open",
      requireMention: false,
    },
    discord: {
      enabled: true,
      token: { source: "env", provider: "default", id: "DISCORD_BOT_TOKEN" },
      dmPolicy: "disabled",
      dm: { enabled: false },
      groupPolicy: "allowlist",
    },
  },
  agents: {
    defaults: {
      model: { primary: "openai/gpt-6-astra" },
      models: {
        "openai/gpt-6-astra": { params: { fastMode: true } },
      },
    },
  },
}
ssh <vm-name>.exe.xyz 'openclaw config patch --stdin --dry-run' < ./openclaw.remote.patch.json5
ssh <vm-name>.exe.xyz 'openclaw config patch --stdin' < ./openclaw.remote.patch.json5
ssh <vm-name>.exe.xyz 'openclaw gateway restart && openclaw health'

当嵌套的允许列表应完全替换为补丁值时,请使用 --replace-path,例如替换 Discord 频道允许列表:

ssh <vm-name>.exe.xyz 'openclaw config patch --stdin --replace-path "channels.discord.guilds[\"123\"].channels"' < ./discord.patch.json5

完整的频道配置参考请参阅 Discord 和 Slack。

远程访问

exe.dev 负责处理远程访问的身份验证。默认情况下,来自 8000 端口的 HTTP 流量会通过电子邮件认证转发至 https://<vm-name>.exe.xyz。

更新

openclaw update

有关频道切换和手动恢复,请参阅 更新。

本页原文 Markdown:在 AtomGit 查看·内容源自开源项目 cl/openclaw