OpenClaw Reference Setup: 6-Week Production Use Case with Security Architecture

✍️ OpenClawRadar📅 Published: March 28, 2026🔗 Source
OpenClaw Reference Setup: 6-Week Production Use Case with Security Architecture
Ad

Production Setup Details

This is a real-world OpenClaw implementation running continuously for 6 weeks on dedicated hardware. The user isn't a developer but built this over evenings and weekends while working in industrial engineering at a chemical plant.

Hardware and Core Configuration

  • Hardware: Mac Mini M4 with 24GB RAM, dedicated
  • Model cascade: Claude Sonnet → MiniMax → Qwen local (3 tiers)
  • Custom tools: 15+
  • Cron jobs: 12 running daily
  • Uptime: 6 weeks continuous
  • Cost: ~$30-50/month
  • Daily messages: 20-50

Daily Functions

  • Morning briefing: Every day at 5:08am with weather, calendar, emails, market data, reminders, and a vocabulary word. Assembled locally from cached sources.
  • Invoice scanning: Reads GMX, iCloud and Gmail inboxes, downloads PDF invoices, categorises them with AI, and files them. First run processed 61 PDFs sorted into 11 categories in one pass.
  • Voice messages: Transcribes locally with Whisper (no cloud), processes, and responds. No audio ever leaves the machine.
  • iCloud bridge: Bidirectional file sync. Files dropped into a folder on iPhone get picked up by the agent, which can drop files back the same way.
Ad

Security Architecture

The creator emphasizes most setups have exec.security: "off", which is vulnerable to prompt injection. This implementation includes:

  • Exec approvals with ~57 allowlisted binaries
  • HTTP egress locked to a domain allowlist (no curl to unknown URLs)
  • SMTP egress locked to an approved recipient list
  • File integrity monitoring on 30+ critical files with SHA256 checksums
  • Injection detection on every external input — email, calendar, web, voice
  • Memory validation before every write (no poisoning via email content)
  • Purple Team audit with MITRE ATT&CK mapping

Security score improved from 3/10 to 7.5/10.

Lessons Learned

  • sandbox.mode: "all" silently denies every exec call with no error or log
  • Memory explodes without hard limits. Implemented 200-line cap on daily logs plus weekly distillation into long-term memory
  • Shell pipes always trigger approvals even when every binary is allowlisted. Solution: wrapper scripts
  • exec-approvals.json must NOT be immutable as OpenClaw writes to it on every exec

Repository and Licensing

Everything is open-sourced at https://github.com/Atlas-Cowork/openclaw-reference-setup under MIT license. Includes templates, security architecture, tool catalog, and cron configs.

📖 Read the full source: r/openclaw

Ad

👀 See Also

Mass Parallelizing Claude Code: Lessons from Building a 220K-Line App
Use Cases

Mass Parallelizing Claude Code: Lessons from Building a 220K-Line App

A developer with no formal coding background built a full-stack mobile app using Claude Code, running 3-4 parallel instances to process 4 billion tokens across 500+ files. Key techniques include handoff documents, CLAUDE.md files, custom slash commands, and systematic codebase audits.

OpenClawRadar
Non-developer builds personalized AI news editor with Claude
Use Cases

Non-developer builds personalized AI news editor with Claude

A non-technical user created a personalized daily news briefing system using Claude AI, starting with a simple summarization prompt and evolving into a full toolkit with context-aware filtering and bias checking.

OpenClawRadar
Claude AI Agents Build Simulator, Optimize Game Algorithm to Beat Human Score
Use Cases

Claude AI Agents Build Simulator, Optimize Game Algorithm to Beat Human Score

A developer tested Claude AI agents on the programming game The Farmer Was Replaced by having them build a Python simulator of the game, then iteratively develop a sunflower harvesting algorithm. The AI achieved a time of 5:21, beating the developer's personal best and reaching rank 30 on the global leaderboard.

OpenClawRadar
Using a smaller model as a runtime hygiene layer improves OpenClaw agent reliability
Use Cases

Using a smaller model as a runtime hygiene layer improves OpenClaw agent reliability

A developer found that adding a second, smaller model to act as a runtime hygiene layer for a Qwen 3.5 27B agent in OpenClaw significantly improved reliability, moving from needing session resets every 20-30 minutes to sustained single-session operation.

OpenClawRadar