KubeClaw

OpenClaw for Kubernetes, with guardrails.

Secure defaults. Predictable upgrades. Observable behavior across clusters.

bash
curl -fsSL https://kubeclaw.ai/install.sh | bash

Prefer Helm or GitOps workflows? Use the OCI chart as a subchart. See docs/installation.

What you get

A production Kubernetes platform for OpenClaw with secure defaults, deterministic upgrades, and first-class observability. Built for platform teams that need governance, auditable operations, and day-2 control from kubectl.

Security & Networking

Harden cluster boundaries, control network paths, and reduce deployment drift with secure defaults.

Egress DNS Filtering

Default-deny outbound via Blocky. Explicit allow/deny lists, threat blocklists, country TLD blocking, and full query logging.

NetworkPolicy Scaffolding

Policy templates are included so you can lock down ingress and egress flows with a least-privilege baseline.

Digest-Pinned Images

Each release is validated against a candidate image. Chart defaults ship with exact tag + digest. No silent drift.

Tailscale Integration

Expose the gateway onto your tailnet without public ingress. SSH into the pod from any enrolled device.

Gateway API Routing

Single-hostname path-based routing via HTTPRoutes. Optional bundled Envoy Gateway controller or bring your own.

Observability & Operations

Get complete runtime signals and predictable day-2 operations for cluster and OpenClaw lifecycle management.

Wide Events Observability

Logs, metrics, traces, and K8s events unified in ClickHouse via OpenTelemetry. Search with HyperDX. One backend, not four.

Diagnostics CronJob

Periodic health checks run openclaw doctor and surface drift early, before outages become incidents.

Backup & Restore

Scheduled S3 backups via rclone CronJob, pre-delete hooks on helm uninstall, and documented restore from CSI snapshots, tarballs, or S3.

GitOps-Friendly Config

Declare your desired openclaw.json. The chart handles merge or overwrite via initContainer. Reconcile, don't imperative.

StatefulSet with PVC

Durable storage at /home/node/.openclaw. No ephemeral surprises, no data loss on pod restarts.

AI & Extensibility

Extend agent capabilities with built-in model routing, browser automation tooling, and workflow integrations.

QMD Hybrid Search

Local-first memory backend combining BM25 full-text, vector similarity, and MMR reranking. Auto-indexes agent knowledge via scheduled CronJobs.

LiteLLM Proxy

Per-agent virtual keys, budget caps, model fallback routing, and semantic caching. One endpoint for every LLM provider.

SkillStacks

Composable skill bundles pulled from playbooks, clawhub, or npm registries and installed at deploy time.

Obsidian Vault

PVC-backed markdown vault mounted at /vaults/obsidian, pre-wired for task and knowledge workflows.

Chromium Deployment

Standalone Chromium deployment with CDP on port 9222. Browser automation without host dependencies.

Need more?

Multi-tenancy, enterprise egress controls, SSO, policy-as-code, backup hooks, and signed OCI distribution for Kubernetes environments with strict compliance and platform standards.