The KAGAMI mark КАГАМИ
kagami.bg/academy · lesson · machine-readable viewUPDATED 2026-10-03
IDENTITY
module
GX10-04-31 · OpenClaw on GX10: a personal AI agent
series
GX10 (local AI server class: NVIDIA GB10, e.g. ASUS Ascent GX10 / DGX Spark)
level
Intermediate
duration
about 1 h
prerequisites
A GB10-class machine with DGX OS (Arm64), terminal access, Node.js 24.16+ or 26.1+, access to a model (cloud API key or local Ollama)
trust_label
UPDATED 2026-10-03 (against official OpenClaw documentation and npm). NOT TESTED on a GB10 machine
versions
OpenClaw 2026.9.8 on npm (2026-10-03). Versions change quickly: run openclaw status
language
human view: bg · english edition: /en/academy/gx10/ (same file name)
previous / next
GX10 series index / 04-32_NemoClaw.html
PURPOSE

Install OpenClaw, a personal AI agent with tools, on a GB10-class server. Run the Gateway as a service, reach the dashboard through an SSH tunnel without exposing the machine, give the agent a first read-only task under human approval, and understand sandboxing and the security audit.

KEY CONCEPTS
COMMANDS / PATHS
CHECKLIST
NEXT MODULE

04-32 · NemoClaw: OpenClaw in a sandbox on GX10 (04-32_NemoClaw.html) · series index: kagami.bg/academy/gx10/ · related series: kagami.bg/academy/openclaw/ · offer: Quick experiment (kagami.bg/stalbata/)

SOURCES
TAGS
gx10nvidia-gb10arm64openclawai-agentgatewaytoolssandboxself-hosting
UPDATED · 03.10.2026

OpenClaw on GX10: a Personal AI Agent on Your Own Machine

An agent is not a chat that only answers: it has tools. It runs commands, reads files and opens websites. OpenClaw is an open personal agent with one persistent process (the Gateway) that connects a model, chat channels and tools. Here we install it on a server of the NVIDIA GB10 class, reach its dashboard through an SSH tunnel and give it a first task under our approval.

⏱ ~1 h Intermediate GX10 NVIDIA GB10 · Arm64 · 128 GB unified memory OpenClaw · Gateway · tools
OpenClaw (Gateway and tools)🔒 local Model: local through Ollama🔒 local Model: cloud provider (optional)🌐 global
🔄
UPDATED · 03.10.2026 — what changed
The lesson was written anew. The old version presented "OpenClaw" as an LLM-controlled robotic arm (a simulator, a board of about 100 US dollars, sample code with built-in models and prices in dollars). We could not find that description in the official OpenClaw documentation — there OpenClaw is a personal AI assistant with a Gateway and tools. So we removed the robot, the simulator, the code with made-up tools and every number listed there (latency, memory use). We added: what OpenClaw really is, installation by the current documentation (Node.js 24.16+ or 26.1+), the Gateway as a service, dashboard access through an SSH tunnel, and the rules for tools and sandboxing. The voice control that the next old module promised is covered in OpenClaw voice control with Whisper — we do not repeat it here. The current npm release on 03.10.2026 is 2026.9.8; versions change quickly.
⚠️
What we have not run ourselves
We had no GB10-class machine during the check. The commands were checked against the official OpenClaw documentation as of 03.10.2026, but we have not run them on such a machine — which is why there is no "TESTED" label. Also unchecked: whether the Gateway starts by itself after the machine reboots, the speed of a local model on GB10, and how the agent behaves with a particular model.

01What you will learn

02Before you start

03Steps

  1. What OpenClaw is (and is not)

    OpenClaw is a personal AI agent. One process — the Gateway — holds the sessions, connects the model to chat channels (Discord, Telegram and others) and gives it tools. The dashboard (Control UI) is a web page of the same process. Do not confuse it with Open WebUI: that is only a chat page for models, without tools. A detailed "which is which" table is in the series cheat sheet.

    PartWhat it is for
    GatewayThe persistent process: sessions, channels, tools, dashboard. Default port 18789
    ModelA cloud provider or a local one (Ollama). It decides what to do
    ToolsTyped actions the agent can call: running commands (exec), a browser, web search, messages
    SkillsSKILL.md files with instructions on how to do a particular job
    PluginsAdd tools, providers, channels and hooks

    How one turn works (per the documentation): a message arrives → context and skills are assembled → the model answers or asks for a tool → the tool runs → the result goes back to the model → a final reply comes out. Turns in one session run one at a time so that tools do not collide.

  2. Check the machine

    bash · on the machine
    uname -m
    node --version
    df -h ~

    You expect aarch64 and a matching Node.js version (24.16+ or 26.1+). If Node is older, install it by the OpenClaw documentation before you continue.

  3. Install OpenClaw

    The official script is for macOS and Linux. A script piped straight into bash is convenient but you trust it blindly — so download it, read it, and only then run it.

    bash · on the machine
    curl -fsSL https://openclaw.ai/install.sh -o openclaw-install.sh
    less openclaw-install.sh      # read what it does
    bash openclaw-install.sh

    The script starts the first-run wizard by itself. Choose Quick start: if it finds a key or a login for Claude Code or Codex CLI, it uses it and checks with a real request; otherwise it sends you to manual provider setup. Custom setup shows all the steps. A way without installing: npx openclaw@latest. You can return to the settings later with openclaw configure.

    After Quick start the Gateway runs in the foreground of this terminal. Stop it with Ctrl+C and run it as a service:

    bash
    openclaw gateway install
    openclaw gateway status
    openclaw status

    On Linux the service is a systemd user unit. You expect the Gateway on port 18789. ⚠️ Whether it starts by itself after a reboot without you logging in — we have not checked.

  4. Open the dashboard from your own computer

    By default the Gateway listens only on the machine itself (loopback). That is right: do not open it to the network. From your computer you reach it through an SSH tunnel — a protected corridor that opens no port anywhere.

    bash · on your computer
    ssh -L 18789:localhost:18789 <user>@<server-address>

    Leave the connection open and open http://localhost:18789 in your browser. If you work directly on the machine, run openclaw dashboard. If the dashboard says the origin is not allowed, see the cheat sheet (keys gateway.publicOrigin and gateway.controlUi.allowedOrigins); do not switch on the "dangerous" modes.

    ✅
    Beyond loopback — only with authentication
    If you ever change gateway.bind to anything other than loopback, the documentation requires authentication. Treat the dashboard and its addresses as a secret: whoever has them talks to the agent.
  5. Choose a model

    An agent is only as good as the model behind it. Two paths:

    • A cloud provider 🌐 global — the easiest; every request and every tool result goes to the provider.
    • A local model through Ollama 🔒 local — the data stays on the machine. On GB10 the memory is unified for the processor and the GPU (128 GB), so the model, the system and the containers share it. The Ollama address looks like http://<address>:<port> without /v1, otherwise tools break — details and sample settings are in the cheat sheet, and how to choose a model is in the performance lesson.

    We do not repeat the setup here, so that there is one place for it. ⚠️ We have not measured the speed of a local model on your machine.

  6. A first task — read-only

    In the dashboard write something harmless and useful: "Look through the file list in the test folder and tell me which are the largest. Do not change or delete anything." Watch which tools the agent asks for and what each returns. That is how you learn how the model "thinks" before you give it anything important.

    In the chat, commands such as /status (session state), /new (archives the session and starts a new one) and /reset (resets it in place) work.

    ✅
    A human approves every action with a real effect
    Deleting, sending a message, paying, publishing, changing settings — only after your “yes”. Start with a folder that holds nothing valuable and with read-only rights.
  7. Security — three moves

    bash
    openclaw security audit
    openclaw doctor
    openclaw logs --follow
    1. Audit: openclaw security audit after every larger change; review the result. In detail: OpenClaw security.
    2. Who can write: allow only known people (for Discord — pairing or an allow list).
    3. Sandbox: according to the documentation tool execution is not sandboxed by default. You switch it on with agents.defaults.sandbox; the Gateway stays on the machine and only the tools move. The documentation itself says this is not a perfect boundary, but it limits file and process access when the model makes a mistake.

    How to make the sandbox tighter — with a separate environment, network policy and keys kept outside it — is the topic of the next lesson: NemoClaw.

04Check

Test

1. Which process in OpenClaw connects the model to the chat channels and the tools?

2. Which address does the Gateway listen on by default?

3. How do you reach the dashboard of a remote machine without opening the network?

4. What is the default state of the sandbox for tools in OpenClaw?

05What's next

06Sources

  1. OpenClaw: getting started 🌐 global — Node.js 24.16+/26.1+, install script, openclaw gateway install, port 18789.
  2. OpenClaw: the agent loop — how one turn is processed.
  3. OpenClaw: tools, skills and plugins — the difference between the three.
  4. OpenClaw: sandboxing · Gateway security — off by default; not a perfect boundary.
  5. openclaw on npm — current release 2026.9.8 as of 03.10.2026.
  6. ASUS Ascent GX10: tech specs · NVIDIA DGX Spark: hardware — 128 GB unified memory.