KubeClaw
OpenClaw for Kubernetes, with guardrails.
Secure defaults. Predictable upgrades. Observable behavior across clusters.
curl -fsSL https://kubeclaw.ai/install.sh | bash
Prefer Helm or GitOps workflows? Use the OCI chart as a subchart. See docs/installation.
What you get
A production Kubernetes platform for OpenClaw with secure defaults, deterministic upgrades, and first-class observability. Built for platform teams that need governance, auditable operations, and day-2 control from kubectl.
Security & Networking
Harden cluster boundaries, control network paths, and reduce deployment drift with secure defaults.
Egress DNS Filtering
Default-deny outbound via Blocky. Explicit allow/deny lists, threat blocklists, country TLD blocking, and full query logging.
NetworkPolicy Scaffolding
Policy templates are included so you can lock down ingress and egress flows with a least-privilege baseline.
Digest-Pinned Images
Each release is validated against a candidate image. Chart defaults ship with exact tag + digest. No silent drift.
Tailscale Integration
Expose the gateway onto your tailnet without public ingress. SSH into the pod from any enrolled device.
Gateway API Routing
Single-hostname path-based routing via HTTPRoutes. Optional bundled Envoy Gateway controller or bring your own.
Observability & Operations
Get complete runtime signals and predictable day-2 operations for cluster and OpenClaw lifecycle management.
Wide Events Observability
Logs, metrics, traces, and K8s events unified in ClickHouse via OpenTelemetry. Search with HyperDX. One backend, not four.
Diagnostics CronJob
Periodic health checks run openclaw doctor and surface drift early, before outages become incidents.
Backup & Restore
Scheduled S3 backups via rclone CronJob, pre-delete hooks on helm uninstall, and documented restore from CSI snapshots, tarballs, or S3.
GitOps-Friendly Config
Declare your desired openclaw.json. The chart handles merge or overwrite via initContainer. Reconcile, don't imperative.
StatefulSet with PVC
Durable storage at /home/node/.openclaw. No ephemeral surprises, no data loss on pod restarts.
AI & Extensibility
Extend agent capabilities with built-in model routing, browser automation tooling, and workflow integrations.
QMD Hybrid Search
Local-first memory backend combining BM25 full-text, vector similarity, and MMR reranking. Auto-indexes agent knowledge via scheduled CronJobs.
LiteLLM Proxy
Per-agent virtual keys, budget caps, model fallback routing, and semantic caching. One endpoint for every LLM provider.
SkillStacks
Composable skill bundles pulled from playbooks, clawhub, or npm registries and installed at deploy time.
Obsidian Vault
PVC-backed markdown vault mounted at /vaults/obsidian, pre-wired for task and knowledge workflows.
Chromium Deployment
Standalone Chromium deployment with CDP on port 9222. Browser automation without host dependencies.
Need more?
Multi-tenancy, enterprise egress controls, SSO, policy-as-code, backup hooks, and signed OCI distribution for Kubernetes environments with strict compliance and platform standards.