Hardened OpenClaw on AWS with Terraform
Details
- External ID
- 47370299
- Source
- HN
- Company
- —
- Product
- Hardened OpenClaw on AWS with Terraform
- Website domain
- github.com
- Launched
- March 13, 2026
- Cohort
- —
- Upvotes
- 10
- Upvotes percentile
- 0.5781057810578106
- Tags
- —
- Fetched at
- Sept. 7, 2026, 9:26 p.m.
- Updated at
- Sept. 7, 2026, 9:26 p.m.
Description
I work on AWS infrastructure (ex-Percona, Box, Dropbox, Pinterest). When OpenClaw blew up, I wanted to run it properly on AWS and was surprised by the default deployment story. The Lightsail blueprint shipped with 31 unpatched CVEs. The standard install guide uses three separate curl-pipe-sh patterns as root. Bitsight found 30,000+ exposed instances in two weeks. OpenClaw's own maintainer said "if you can't understand how to run a command line, this is far too dangerous."So I built a Terraform module that replaces the defaults with what I'd consider production-grade:* Cognito + ALB instead of a shared gateway token (per-user identity, MFA) * GPG-verified APT packages instead of curl|bash * systemd with ProtectHome=tmpfs and BindPaths sandboxing * Secrets Manager + KMS instead of plaintext API keys * EFS for persistence across instance replacement * CloudWatch logging with 365-day retention Bedrock is the default LLM provider so it works without any API keys. One terraform apply. Full security writeup: https://infrahouse.com/blog/2026-03-09-deploying-openclaw-on...I'm sure I've missed things. What would you add or do differently for running an autonomous agent with shell access on a shared server?
Enrichment
- Theme
- self-hosted infrastructure and security tools
- Vertical
- Horizontal
- Function
- Dev tools
- Audience
- Developer
- AI stance
- Not AI
- Project type
- Hobby / open-source project
- Normalized one-liner
- openclaw infrastructure on aws
- Manually corrected
- False
Could you build this?
Yes Writing modular Terraform configurations to deploy an application securely on AWS (VPC, IAM, ECS/EC2, security groups, KMS) is a sweet spot for AI coding assistants.
Discussion
3 comments analyzed.
Competitors mentioned: Kubiya skill runtime (skill-ai.dev)
Concerns raised: CVE baseline hygiene in default deployments, Agent-level credential scoping not currently addressed, Security risk of AI agents deployed without hardening
Feature requests: Agent-level credential scoping
Competitors
Other products that read as similar to this one — 238 launches clear the similarity bar, closest 8 shown.
Attention rank: #111 of 239 (itself plus its competitors, highest first — normalized so YC and Product Hunt are compared fairly).
Launched 134 days after the earliest competitor.
- Klaus · hn · 2026-03-11 · 160 upvotes · similarity 0.56
- CloudSlash · hn · 2026-01-05 · 5 upvotes · similarity 0.49
- I built managed OpenClaw hosting with 60s provisioning in 6 days · hn · 2026-02-11 · 9 upvotes · similarity 0.48
- Open source setup to self-host OpenClaw instances on any host · hn · 2026-02-09 · 7 upvotes · similarity 0.48
- ClawDeploy · hn · 2026-02-12 · 6 upvotes · similarity 0.48
- ClawShell, Process-Level Isolation for OpenClaw Credentials · hn · 2026-02-19 · 10 upvotes · similarity 0.48
- Clawbernetes · hn · 2026-02-20 · 5 upvotes · similarity 0.47
- OpenShears · hn · 2026-02-04 · 7 upvotes · similarity 0.47
Other launches for this product
- No other launches for this product.
Same idea, different domain
Nobody's really built a dev tools tool for Sales yet.