A professional-grade, zero-cost DevOps stack for running the OpenClaw AI Agent on Google Cloud Platform using your Google AI Subscription (Gemini 3).
- Infrastructure: GCP Spot VM (
e2-medium) in Stockholm (europe-north2). - Storage: 10GB Persistent Disk for Agent memory.
- Brain: Google Gemini 3 Pro/Flash via the
opencode-antigravity-authbridge. - Interface: Telegram (Bot API).
- CI/CD: GitHub Actions + Terraform Cloud.
- Push to
mainperforms: targeted core infra apply (registry/network/dns), Docker build+push, then VM update with the new Git SHA image tag.
- Push to
- GCP Project: A Google Cloud project with billing enabled (using your $10 credit).
- Terraform Cloud: A free account at app.terraform.io.
- OpenCode CLI: Installed locally (
bun install -g opencode-ai).
- Sign up/Login to app.terraform.io.
- Use/Create the organization
aasan_dev. - Create a new Workspace named
openclaw-gitopsusing the API-driven workflow. - Add the following Workspace Variables:
GOOGLE_CREDENTIALS: Paste your GCP Service Account JSON key (ensure all newlines are removed, it should be a single string).project_id: Your Google Cloud Project ID.
Add the following to your GitHub Repo Secrets:
TF_API_TOKEN: Your Terraform Cloud API token.GCP_PROJECT_ID: Your Google Cloud Project ID.GCP_CREDENTIALS: Your GCP Service Account JSON key.TELEGRAM_BOT_TOKEN: Telegram bot token from @BotFather.
The version of OpenClaw is pinned in docker/Dockerfile. To update:
- Change the version tag in
docker/Dockerfile(e.g.,v2026.x.y). - Push to
main. The CI/CD pipeline will build a new custom image, push it to your private Google Artifact Registry, and update your server.
Since the server is headless, you must authenticate locally and sync the session:
- On your laptop:
opencode auth login # Select "Antigravity" and complete the browser login. - Transfer the session to the VM (via IAP):
The session is stored in
~/.config/opencode/. Copy this folder to the VM's persistent mount at/mnt/openclaw/config/opencode/using IAP tunneling.gcloud compute scp --recurse ~/.config/opencode openclaw-agent:/mnt/openclaw/config/ \ --zone=europe-north2-a --tunnel-through-iap
- Create a bot with @BotFather:
- Run
/newbotand follow the prompts. - Copy the token and add it to GitHub Secrets as
TELEGRAM_BOT_TOKEN.
- Run
- Deploy the change (push to
main). The VM will restart OpenClaw with the new token. - (Optional) If you want the bot to read all group messages, disable privacy mode with:
- In @BotFather:
/setprivacy→ Disable - Remove + re-add the bot to each group after changing privacy.
- In @BotFather:
The OpenClaw debugging UI is not exposed to the internet for security. To open it, create a secure SSH tunnel from your laptop:
gcloud compute ssh openclaw-agent \
--zone=europe-north2-a \
--tunnel-through-iap \
-- -L 18789:localhost:18789Once running, open your browser to http://localhost:18789.
- Gateway Token:
dummy(change this iniac/scripts/startup.shfor production). - Pair the browser once (required):
docker compose exec openclaw node /app/openclaw.mjs devices list docker compose exec openclaw node /app/openclaw.mjs devices approve <requestId>
To see what the agent is thinking or debug Telegram connection issues:
gcloud compute ssh openclaw-agent \
--zone=europe-north2-a \
--tunnel-through-iap \
--command="sudo docker logs -f openclaw-openclaw-1"For Telegram, send a DM to your bot from your personal Telegram account.
- Open Telegram and search for your bot username (the one you created via @BotFather).
- Send a message like
"ping". - If the agent is connected, you will see it process the message in the logs and respond.
Note: Telegram DMs default to pairing. If this is your first message, the bot will reply with a pairing code; approve it with:
docker compose exec openclaw node /app/openclaw.mjs pairing list telegram docker compose exec openclaw node /app/openclaw.mjs pairing approve telegram <CODE>
- IaC Quality Gates: Every pull request and push to main is validated via
terraform fmt,terraform validate, and TFLint (with Google-specific rules). - Code Linting: Node.js and configuration files are linted and formatted via Biome.
- Immutable Artifacts: Deployments use specific Docker image tags (Git SHA) pushed to a private Google Artifact Registry.
- Least Privilege: The system uses a dedicated GCP Service Account with narrowly defined roles for deployment and runtime.
This setup is designed to stay under $10/month:
- Spot VM: ~$6.00
- Static IP: ~$3.60
- Storage: ~$0.40
- Total: ~$10.00 (Fully covered by Google's $10 monthly credit).
- OpenClaw: by Peter Steinberger.
- Antigravity Auth: by NoeFabris.
- Infrastructure: Designed by Antigravity (Google DeepMind).