# AI Core — OpenClaw gateway. # Reproducible: this same file runs on the ws VM now and on AWS EC2 later. # Image + gateway port (18789) + state path verified against OpenClaw docs. services: gateway: image: ghcr.io/openclaw/openclaw:latest container_name: ai-core-gateway restart: unless-stopped env_file: .env ports: # Loopback only. The gateway has no auth by default — never bind 0.0.0.0. # Reach it over Tailscale or an SSH tunnel (see README). - "127.0.0.1:18789:18789" volumes: # Persistent state: config, agent workspaces, sessions. Gitignored. - ./state:/home/node/.openclaw # Canonical agent definitions (read-only reference for the register step). # ponytail: registration is a documented manual step (openclaw agents add); # confirm the workspace path contract on first run. Ceiling: not yet automated. - ./agents:/opt/ai-core/agents:ro # OpenClaw OOMs (exit 137) under ~2GB; 4GB recommended. mem_limit: 4g healthcheck: test: ["CMD", "wget", "-qO-", "http://127.0.0.1:18789/healthz"] interval: 30s timeout: 5s retries: 3 start_period: 40s