Download docker-compose.yml from SaylorTwift/openclaw: direct link, hf CLI and curl.
- Browser
- Download file 5.98 kB
-
https://huggingface.co/SaylorTwift/openclaw/resolve/main/docker-compose.yml
- Command line
-
hf download hf://SaylorTwift/openclaw/docker-compose.yml
-
curl -L -o docker-compose.yml https://huggingface.co/SaylorTwift/openclaw/resolve/main/docker-compose.yml
5.98 kB
| services: | |
| openclaw-gateway: | |
| image: ${OPENCLAW_IMAGE:-openclaw:local} | |
| build: . | |
| env_file: | |
| - path: .env | |
| required: false | |
| environment: | |
| HOME: /home/node | |
| OPENCLAW_HOME: /home/node | |
| TERM: xterm-256color | |
| # Pin container-side state, workspace, and config paths so host values written to | |
| # `.env` (used by Compose for the bind-mount source below) cannot leak | |
| # into runtime code that resolves these env vars inside the container. | |
| # Without this override, a macOS host path like /Users/<you>/.openclaw/... | |
| # imported from .env caused first-reply `mkdir '/Users'` EACCES failures | |
| # in Linux Docker (#77436). | |
| OPENCLAW_STATE_DIR: /home/node/.openclaw | |
| OPENCLAW_CONFIG_PATH: /home/node/.openclaw/openclaw.json | |
| OPENCLAW_CONFIG_DIR: /home/node/.openclaw | |
| OPENCLAW_WORKSPACE_DIR: /home/node/.openclaw/workspace | |
| # .env controls host publishing; in-container clients use the fixed listener. | |
| OPENCLAW_GATEWAY_PORT: "18789" | |
| OPENCLAW_GATEWAY_TOKEN: ${OPENCLAW_GATEWAY_TOKEN:-} | |
| OPENCLAW_ALLOW_INSECURE_PRIVATE_WS: ${OPENCLAW_ALLOW_INSECURE_PRIVATE_WS:-} | |
| # Empty means auto: Bonjour disables itself in detected containers. | |
| # Set 0 only on host/macvlan/mDNS-capable networks; set 1 to force off. | |
| OPENCLAW_DISABLE_BONJOUR: ${OPENCLAW_DISABLE_BONJOUR:-} | |
| # OpenTelemetry export is outbound OTLP/HTTP from the Gateway. Prometheus | |
| # uses the existing authenticated Gateway route; it does not need a port. | |
| OTEL_EXPORTER_OTLP_ENDPOINT: ${OTEL_EXPORTER_OTLP_ENDPOINT:-} | |
| OTEL_EXPORTER_OTLP_TRACES_ENDPOINT: ${OTEL_EXPORTER_OTLP_TRACES_ENDPOINT:-} | |
| OTEL_EXPORTER_OTLP_METRICS_ENDPOINT: ${OTEL_EXPORTER_OTLP_METRICS_ENDPOINT:-} | |
| OTEL_EXPORTER_OTLP_LOGS_ENDPOINT: ${OTEL_EXPORTER_OTLP_LOGS_ENDPOINT:-} | |
| OTEL_EXPORTER_OTLP_PROTOCOL: ${OTEL_EXPORTER_OTLP_PROTOCOL:-http/protobuf} | |
| OTEL_EXPORTER_OTLP_TRACES_PROTOCOL: ${OTEL_EXPORTER_OTLP_TRACES_PROTOCOL:-} | |
| OTEL_EXPORTER_OTLP_METRICS_PROTOCOL: ${OTEL_EXPORTER_OTLP_METRICS_PROTOCOL:-} | |
| OTEL_EXPORTER_OTLP_LOGS_PROTOCOL: ${OTEL_EXPORTER_OTLP_LOGS_PROTOCOL:-} | |
| OTEL_SERVICE_NAME: ${OTEL_SERVICE_NAME:-} | |
| OTEL_SEMCONV_STABILITY_OPT_IN: ${OTEL_SEMCONV_STABILITY_OPT_IN:-} | |
| OPENCLAW_OTEL_PRELOADED: ${OPENCLAW_OTEL_PRELOADED:-} | |
| CLAUDE_AI_SESSION_KEY: ${CLAUDE_AI_SESSION_KEY:-} | |
| CLAUDE_WEB_SESSION_KEY: ${CLAUDE_WEB_SESSION_KEY:-} | |
| CLAUDE_WEB_COOKIE: ${CLAUDE_WEB_COOKIE:-} | |
| TZ: ${OPENCLAW_TZ:-UTC} | |
| volumes: | |
| - "${OPENCLAW_CONFIG_DIR:-${HOME:-/tmp}/.openclaw}:/home/node/.openclaw" | |
| - "${OPENCLAW_WORKSPACE_DIR:-${HOME:-/tmp}/.openclaw/workspace}:/home/node/.openclaw/workspace" | |
| - "${OPENCLAW_AUTH_PROFILE_SECRET_DIR:-${HOME:-/tmp}/.openclaw-auth-profile-secrets}:/home/node/.config/openclaw" | |
| ## Uncomment the lines below to enable sandbox isolation | |
| ## (agents.defaults.sandbox). Requires Docker CLI in the image | |
| ## (build with --build-arg OPENCLAW_INSTALL_DOCKER_CLI=1) or use | |
| ## scripts/docker/setup.sh with OPENCLAW_SANDBOX=1 for automated setup. | |
| ## Set DOCKER_GID to the host's docker group GID (run: stat -c '%g' /var/run/docker.sock). | |
| # - /var/run/docker.sock:/var/run/docker.sock | |
| # group_add: | |
| # - "${DOCKER_GID:-999}" | |
| # Let bundled local-model providers reach host-side LM Studio/Ollama via | |
| # http://host.docker.internal:<port>. Docker Desktop usually provides this | |
| # alias; the host-gateway mapping makes it work on Linux Docker Engine too. | |
| cap_drop: | |
| - NET_RAW | |
| - NET_ADMIN | |
| security_opt: | |
| - no-new-privileges:true | |
| extra_hosts: | |
| - "host.docker.internal:host-gateway" | |
| ports: | |
| - "${OPENCLAW_GATEWAY_PORT:-18789}:18789" | |
| - "${OPENCLAW_BRIDGE_PORT:-18790}:18790" | |
| - "${OPENCLAW_MSTEAMS_PORT:-3978}:3978" | |
| init: true | |
| restart: unless-stopped | |
| command: | |
| [ | |
| "node", | |
| "dist/index.js", | |
| "gateway", | |
| "--bind", | |
| "${OPENCLAW_GATEWAY_BIND:-lan}", | |
| "--port", | |
| "18789", | |
| ] | |
| healthcheck: | |
| test: | |
| [ | |
| "CMD", | |
| "node", | |
| "dist/docker-healthcheck.js", | |
| ] | |
| interval: 30s | |
| timeout: 5s | |
| retries: 5 | |
| start_period: 20s | |
| openclaw-cli: | |
| image: ${OPENCLAW_IMAGE:-openclaw:local} | |
| network_mode: "service:openclaw-gateway" | |
| env_file: | |
| - path: .env | |
| required: false | |
| cap_drop: | |
| - NET_RAW | |
| - NET_ADMIN | |
| security_opt: | |
| - no-new-privileges:true | |
| environment: | |
| HOME: /home/node | |
| OPENCLAW_HOME: /home/node | |
| TERM: xterm-256color | |
| # Pin container-side state, workspace, and config paths so host values written to | |
| # `.env` cannot leak into runtime code via the env_file import (#77436). | |
| OPENCLAW_STATE_DIR: /home/node/.openclaw | |
| OPENCLAW_CONFIG_PATH: /home/node/.openclaw/openclaw.json | |
| OPENCLAW_CONFIG_DIR: /home/node/.openclaw | |
| OPENCLAW_WORKSPACE_DIR: /home/node/.openclaw/workspace | |
| # Shared gateway network namespace: use its listener, not the .env host port. | |
| OPENCLAW_GATEWAY_PORT: "18789" | |
| OPENCLAW_GATEWAY_TOKEN: ${OPENCLAW_GATEWAY_TOKEN:-} | |
| OPENCLAW_ALLOW_INSECURE_PRIVATE_WS: ${OPENCLAW_ALLOW_INSECURE_PRIVATE_WS:-} | |
| BROWSER: echo | |
| CLAUDE_AI_SESSION_KEY: ${CLAUDE_AI_SESSION_KEY:-} | |
| CLAUDE_WEB_SESSION_KEY: ${CLAUDE_WEB_SESSION_KEY:-} | |
| CLAUDE_WEB_COOKIE: ${CLAUDE_WEB_COOKIE:-} | |
| TZ: ${OPENCLAW_TZ:-UTC} | |
| volumes: | |
| - "${OPENCLAW_CONFIG_DIR:-${HOME:-/tmp}/.openclaw}:/home/node/.openclaw" | |
| - "${OPENCLAW_WORKSPACE_DIR:-${HOME:-/tmp}/.openclaw/workspace}:/home/node/.openclaw/workspace" | |
| - "${OPENCLAW_AUTH_PROFILE_SECRET_DIR:-${HOME:-/tmp}/.openclaw-auth-profile-secrets}:/home/node/.config/openclaw" | |
| stdin_open: true | |
| tty: true | |
| init: true | |
| entrypoint: ["node", "dist/index.js"] | |
| depends_on: | |
| - openclaw-gateway | |