Jump to content

OpenClaw on PMSS

From Pulsed Media Wiki

A Pulsed Media seedbox on a current PMSS can run OpenClaw, an open-source AI agent you talk to through a web page or a chat app, inside your own account. One command installs it: install-openclaw install. OpenClaw runs commands as your account, so its gateway token is as powerful as your SSH password. The installer generates that token itself and the gateway will not start without it.

OpenClaw is optional. Nothing is installed until you run the installer, and it does not touch the media stack or the AI coding tools.

What gets installed

Item Where
install-openclaw (the installer and watchdog) ~/bin, on your PATH, shipped by PMSS updates
Node.js 24.21.0, checked against the SHA256 published on nodejs.org ~/.local/share/node-openclaw
OpenClaw ~/.local/share/openclaw
openclaw command ~/bin/openclaw
Configuration, gateway token, logs, workspace ~/.openclaw
Two watchdog lines in your own crontab, both ending in # pmss-openclaw crontab -l

The gateway listens on 127.0.0.1 only, on a port PMSS reserves for your account. The port number is in ~/.openclaw/gateway.port.

Requirements

Installing needs room for about 55,000 files and 1.3 GB. Seedbox accounts have a file-count quota as well as a disk quota, so the file count is usually the limit that matters. Check both with:

quota -s

Check this yourself before installing. The current installer also reads the same numbers before it downloads anything: if 60,000 more files would not fit under your file limit, it stops and says so. On a busy server the first gateway start can take a minute or two.

Installing

Log in over SSH (see Seedbox access via FTP, SSH and SFTP) and run:

install-openclaw install
install-openclaw status

The installer asks for confirmation; --yes skips the question. It does not set up a model provider or a chat channel. Add your own provider key afterwards with OpenClaw's interactive setup:

openclaw configure --section model

Provider and channel settings are OpenClaw's own; the OpenClaw documentation covers them.

Connecting from your computer

The gateway is not reachable from the internet. Open an SSH tunnel from your computer, using the port number from ~/.openclaw/gateway.port:

ssh -L 18789:127.0.0.1:PORT username@server.pulsedmedia.com

Then open http://127.0.0.1:18789/ in your browser. The local number (18789 here) can be any free port on your computer. The web page asks for the gateway token, which this prints:

install-openclaw status --show-token
The OpenClaw page through the SSH tunnel, before the token is entered.

The page also suggests OpenClaw's own token commands. On PMSS the installer creates and stores the token, so read it with install-openclaw status --show-token instead.

Running it

Command What it does
install-openclaw status Shows whether the gateway runs, its port, whether it is listening, and the Node and OpenClaw versions
install-openclaw start Starts the gateway and resets the watchdog
install-openclaw stop Stops the gateway
install-openclaw uninstall Removes the program files, the wrapper and the crontab lines; keeps ~/.openclaw
install-openclaw uninstall --purge Also deletes ~/.openclaw, including the token, credentials and workspace

The crontab watchdog starts the gateway after a server reboot and checks it once a minute. After five failed starts in a row it stops trying until you run install-openclaw start, so a broken configuration does not restart forever. The gateway log is ~/.openclaw/logs/gateway.log.

OpenClaw or the AI coding tools?

For writing code, editing configs and one-off jobs in a shell, use the AI coding tools that already ship with PMSS. They are installed system-wide, cost none of your quota and need no install. OpenClaw is the choice when you want an agent that keeps running between sessions and that you reach from a browser or a chat app instead of a terminal.

Your keys and your data

PMSS supplies no model-provider key. OpenClaw uses the provider and key you configure, and your prompts, plus whatever the agent reads while answering, go to that provider under its terms. Do not paste a key into a command line that ends up in your shell history; openclaw configure asks for it instead. The gateway token file is created readable by your account only.

Using it safely

  • The token equals shell access. Anyone holding it can make the agent run commands as your account. Show it only with status --show-token and keep it out of screenshots and chats.
  • Loopback is not private on a shared server. Other accounts on the same server can connect to 127.0.0.1 too. The token is what keeps them out, which is why the installer refuses to start the gateway without one.
  • Keep the gateway on loopback. Do not change its bind address or publish its port; reach it through the SSH tunnel.
  • A chat channel extends the same access. If you connect OpenClaw to a chat app, everyone who can message the bot can drive your account. Restrict the bot to your own identity before you enable it.

Troubleshooting

install-openclaw: command not found
The server has not yet received the PMSS update that ships the installer. Contact support if you need it sooner.
"No PMSS-reserved port yet"
Same cause: the port is reserved by a full PMSS update.
The installer refuses because of the file quota
The account cannot hold the roughly 55,000 files. Free up files (quota -s shows the count) or move to a plan with a larger quota.
"Gateway did not stay running"
The first start can take a minute or two on a busy server. Wait two minutes, then run install-openclaw status. If it still shows the gateway stopped, the reason is in ~/.openclaw/logs/gateway.log.
"Gateway is still starting"
The first start can take a minute or two. Run install-openclaw status again; listening=yes means it is ready.
Status shows the watchdog gave up
Read ~/.openclaw/logs/gateway.log, fix the cause, then run install-openclaw start.

Pulsed Media seedboxes come with SSH access and per-account installers like this one, so tools such as OpenClaw run inside your own account without root. Plans with more storage also carry a larger file quota, which is what OpenClaw needs: see the seedbox plans.

See also