oclaw/openclaw/docs/gateway/network-model.md
oliver dbbe3add6a 重构主控编排与运行时预热链路,统一工作区提示词/专家调度协议并补齐 wiki 记忆注入与写回闭环。
同时收敛启动与运维脚本默认行为(含 wiki worker)、更新 Admin 可观测性与相关测试,降低首轮时延并提高运行稳定性。

Made-with: Cursor
2026-04-26 08:34:33 +08:00

1.8 KiB

summary read_when title
How the Gateway, nodes, and canvas host connect.
You want a concise view of the Gateway networking model
Network model

Network Model

This content has been merged into Network. See that page for the current guide.

Most operations flow through the Gateway (openclaw gateway), a single long-running process that owns channel connections and the WebSocket control plane.

Core rules

  • One Gateway per host is recommended. It is the only process allowed to own the WhatsApp Web session. For rescue bots or strict isolation, run multiple gateways with isolated profiles and ports. See Multiple gateways.
  • Loopback first: the Gateway WS defaults to ws://127.0.0.1:18789. The wizard creates shared-secret auth by default and usually generates a token, even for loopback. For non-loopback access, use a valid gateway auth path: shared-secret token/password auth, or a correctly configured non-loopback trusted-proxy deployment. Tailnet/mobile setups usually work best through Tailscale Serve or another wss:// endpoint instead of raw tailnet ws://.
  • Nodes connect to the Gateway WS over LAN, tailnet, or SSH as needed. The legacy TCP bridge has been removed.
  • Canvas host is served by the Gateway HTTP server on the same port as the Gateway (default 18789):
    • /__openclaw__/canvas/
    • /__openclaw__/a2ui/ When gateway.auth is configured and the Gateway binds beyond loopback, these routes are protected by Gateway auth. Node clients use node-scoped capability URLs tied to their active WS session. See Gateway configuration (canvasHost, gateway).
  • Remote use is typically SSH tunnel or tailnet VPN. See Remote access and Discovery.