What are OpenClaw and SSL?
OpenClaw is a third-party, self-hosted tool that you run on your own server. Ask Hostvento support if it is supported on your plan.
SSL is a lock for web traffic. It scrambles the data between a visitor and your server so nobody can spy on it. A site with SSL starts with https and shows a padlock.
The usual way is to place Nginx in front of the app. Nginx is a web server. It takes the visitor's request, handles SSL, and passes it on to OpenClaw. This is called a reverse proxy. Certbot is a free tool that gets certificates from Let's Encrypt, a free certificate maker.
This guide assumes OpenClaw already runs on your server on a local port. Replace 3000 below with the real port. The commands are for Ubuntu.
Before you start
- You own a domain name, such as
claw.example.com. - The domain's A record points to your VPS IP address. An A record links a name to a number.
- Ports 80 and 443 are open in your firewall.
Steps
- Log in to your VPS over SSH.
- Install Nginx and Certbot:
sudo apt update sudo apt install nginx certbot python3-certbot-nginx -y - Create a new site file named
/etc/nginx/sites-available/openclawwith this content:
The last two header lines help with live connections, which many apps use.server { listen 80; server_name claw.example.com; location / { proxy_pass http://127.0.0.1:3000; proxy_set_header Host $host; proxy_set_header X-Real-IP $remote_addr; proxy_http_version 1.1; proxy_set_header Upgrade $http_upgrade; proxy_set_header Connection "upgrade"; } } - Switch the site on and test it:
sudo ln -s /etc/nginx/sites-available/openclaw /etc/nginx/sites-enabled/ sudo nginx -t sudo systemctl reload nginx - Ask Certbot for a certificate:
Enter your email and agree to the terms when asked. Choose the option to redirect http to https.sudo certbot --nginx -d claw.example.com - Open
https://claw.example.comin your browser. You should see the padlock.
Renewal
Let's Encrypt certificates last a short time. Certbot normally sets up automatic renewal. Test it with:
sudo certbot renew --dry-run
This pretends to renew without changing anything.
Quick recap
- Point a domain to your VPS and open ports 80 and 443.
- Install Nginx and Certbot.
- Make Nginx pass requests to the OpenClaw port.
- Run
certbot --nginx -d yourdomain. - Test renewal with
--dry-run.