Claim this agent
Agent DossierCLAWHUBSafety 84/100

Xpersona Agent

Self-Host

Deploy and maintain self-hosted services with security, backups, and long-term reliability. Skill: Self-Host Owner: ivangdavila Summary: Deploy and maintain self-hosted services with security, backups, and long-term reliability. Tags: latest:1.0.0 Version history: v1.0.0 | 2026-02-10T16:28:42.265Z | user Initial release Archive index: Archive v1.0.0: 2 files, 2433 bytes Files: SKILL.md (4071b), _meta.json (128b) File v1.0.0:SKILL.md --- name: Self-Host description: Deploy and maintain self-hosted services w

OpenClaw Β· self-declared
465 downloadsTrust evidence available
clawhub skill install kn73vp5rarc3b14rc7wjcw8f8580t5d1:self-host

Overall rank

#62

Adoption

465 downloads

Trust

Unknown

Freshness

Mar 1, 2026

Freshness

Last checked Mar 1, 2026

Best For

Self-Host is best for general automation workflows where OpenClaw compatibility matters.

Not Ideal For

Contract metadata is missing or unavailable for deterministic execution.

Evidence Sources Checked

editorial-content, CLAWHUB, runtime-metrics, public facts pack

Overview

Key links, install path, reliability highlights, and the shortest practical read before diving into the crawl record.

Verifiededitorial-content

Overview

Executive Summary

Deploy and maintain self-hosted services with security, backups, and long-term reliability. Skill: Self-Host Owner: ivangdavila Summary: Deploy and maintain self-hosted services with security, backups, and long-term reliability. Tags: latest:1.0.0 Version history: v1.0.0 | 2026-02-10T16:28:42.265Z | user Initial release Archive index: Archive v1.0.0: 2 files, 2433 bytes Files: SKILL.md (4071b), _meta.json (128b) File v1.0.0:SKILL.md --- name: Self-Host description: Deploy and maintain self-hosted services w Capability contract not published. No trust telemetry is available yet. 465 downloads reported by the source. Last updated 4/15/2026.

No verified compatibility signals465 downloads

Trust score

Unknown

Compatibility

OpenClaw

Freshness

Mar 1, 2026

Vendor

Clawhub

Artifacts

0

Benchmarks

0

Last release

1.0.0

Install & run

Setup Snapshot

clawhub skill install kn73vp5rarc3b14rc7wjcw8f8580t5d1:self-host
  1. 1

    Setup complexity is LOW. This package is likely designed for quick installation with minimal external side-effects.

  2. 2

    Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data.

Evidence & Timeline

Public facts grouped by evidence type, plus release and crawl events with provenance and freshness.

Verifiededitorial-content

Public facts

Evidence Ledger

Vendor (1)

Vendor

Clawhub

profilemedium
Observed Apr 15, 2026Source linkProvenance
Compatibility (1)

Protocol compatibility

OpenClaw

contractmedium
Observed Apr 15, 2026Source linkProvenance
Release (1)

Latest release

1.0.0

releasemedium
Observed Feb 10, 2026Source linkProvenance
Adoption (1)

Adoption signal

465 downloads

profilemedium
Observed Apr 15, 2026Source linkProvenance
Security (1)

Handshake status

UNKNOWN

trustmedium
Observed unknownSource linkProvenance

Artifacts & Docs

Parameters, dependencies, examples, extracted files, editorial overview, and the complete README when available.

Self-declaredCLAWHUB

Captured outputs

Artifacts Archive

Extracted files

2

Examples

0

Snippets

0

Languages

Unknown

Extracted Files

SKILL.md

---
name: Self-Host
description: Deploy and maintain self-hosted services with security, backups, and long-term reliability.
metadata: {"clawdbot":{"emoji":"πŸ–₯️","requires":{"anyBins":["docker","podman"]},"os":["linux","darwin","win32"]}}
---

# Self-Hosting Rules

## Before Installing Anything
- Backups first β€” decide where data lives and how it's backed up before deploying, not after data exists
- Check resource requirements β€” many services need more RAM than expected, OOM kills corrupt data
- Verify the project is actively maintained β€” abandoned projects become security liabilities

## Docker Fundamentals
- Always use named volumes or bind mounts for persistent data β€” anonymous volumes are lost on container removal
- Pin image versions (`nginx:1.25.3` not `nginx:latest`) β€” latest changes unexpectedly and breaks setups
- Set restart policy (`unless-stopped` or `on-failure`) β€” containers don't auto-start after reboot by default
- Use `docker compose down` not `docker compose rm` β€” down handles networks and volumes properly

## Networking
- Never expose database ports to the internet β€” only the reverse proxy should be public
- Use a reverse proxy (Traefik, Caddy, Nginx Proxy Manager) β€” handles SSL, routing, and security in one place
- Create Docker networks per project β€” default bridge network lacks DNS resolution between containers
- Bind admin interfaces to localhost only (`127.0.0.1:8080:8080`) β€” not all traffic needs to be public

## SSL and Domains
- Use automatic SSL with Let's Encrypt β€” Caddy and Traefik do this natively
- For local/LAN access, use a real domain with DNS challenge β€” avoids browser certificate warnings
- Wildcard certificates simplify multi-service setups β€” one cert for *.home.example.com

## Security Essentials
- Change all default passwords immediately β€” bots scan for default credentials within hours
- Enable automatic security updates for the host OS β€” unpatched systems get compromised
- Use fail2ban or equivalent β€” brute force attacks are constant
- Keep services behind authentication (Authelia, Authentik) β€” not everything has built-in auth
- Disable root SSH, use key-only authentication β€” password SSH is a vulnerability

## Backups
- Test restores, not just backups β€” untested backups are wishful thinking
- 3-2-1 rule: 3 copies, 2 different media, 1 offsite β€” local RAID is not backup
- Automate backup schedules β€” manual backups get forgotten
- Back up Docker volumes, not containers β€” containers are ephemeral, data is not

## Monitoring
- Set up uptime monitoring (Uptime Kuma is self-hostable) β€” know when services die before users tell you
- Monitor disk space β€” full disks cause silent failures and corruption
- Log rotation is mandatory β€” Docker logs grow forever by default, fill disks
- Consider resource monitoring (Netdata, Prometheus) β€” spot problems before they're critical

## Maintenance
- Schedule regular update windows β€” services need updates, plan for downtime
- Document everything you deploy β€” future you won't r

_meta.json

{
  "ownerId": "kn73vp5rarc3b14rc7wjcw8f8580t5d1",
  "slug": "self-host",
  "version": "1.0.0",
  "publishedAt": 1770740922265
}

Editorial read

Docs & README

Docs source

CLAWHUB

Editorial quality

ready

Deploy and maintain self-hosted services with security, backups, and long-term reliability. Skill: Self-Host Owner: ivangdavila Summary: Deploy and maintain self-hosted services with security, backups, and long-term reliability. Tags: latest:1.0.0 Version history: v1.0.0 | 2026-02-10T16:28:42.265Z | user Initial release Archive index: Archive v1.0.0: 2 files, 2433 bytes Files: SKILL.md (4071b), _meta.json (128b) File v1.0.0:SKILL.md --- name: Self-Host description: Deploy and maintain self-hosted services w

Full README

Skill: Self-Host

Owner: ivangdavila

Summary: Deploy and maintain self-hosted services with security, backups, and long-term reliability.

Tags: latest:1.0.0

Version history:

v1.0.0 | 2026-02-10T16:28:42.265Z | user

Initial release

Archive index:

Archive v1.0.0: 2 files, 2433 bytes

Files: SKILL.md (4071b), _meta.json (128b)

File v1.0.0:SKILL.md


name: Self-Host description: Deploy and maintain self-hosted services with security, backups, and long-term reliability. metadata: {"clawdbot":{"emoji":"πŸ–₯️","requires":{"anyBins":["docker","podman"]},"os":["linux","darwin","win32"]}}

Self-Hosting Rules

Before Installing Anything

  • Backups first β€” decide where data lives and how it's backed up before deploying, not after data exists
  • Check resource requirements β€” many services need more RAM than expected, OOM kills corrupt data
  • Verify the project is actively maintained β€” abandoned projects become security liabilities

Docker Fundamentals

  • Always use named volumes or bind mounts for persistent data β€” anonymous volumes are lost on container removal
  • Pin image versions (nginx:1.25.3 not nginx:latest) β€” latest changes unexpectedly and breaks setups
  • Set restart policy (unless-stopped or on-failure) β€” containers don't auto-start after reboot by default
  • Use docker compose down not docker compose rm β€” down handles networks and volumes properly

Networking

  • Never expose database ports to the internet β€” only the reverse proxy should be public
  • Use a reverse proxy (Traefik, Caddy, Nginx Proxy Manager) β€” handles SSL, routing, and security in one place
  • Create Docker networks per project β€” default bridge network lacks DNS resolution between containers
  • Bind admin interfaces to localhost only (127.0.0.1:8080:8080) β€” not all traffic needs to be public

SSL and Domains

  • Use automatic SSL with Let's Encrypt β€” Caddy and Traefik do this natively
  • For local/LAN access, use a real domain with DNS challenge β€” avoids browser certificate warnings
  • Wildcard certificates simplify multi-service setups β€” one cert for *.home.example.com

Security Essentials

  • Change all default passwords immediately β€” bots scan for default credentials within hours
  • Enable automatic security updates for the host OS β€” unpatched systems get compromised
  • Use fail2ban or equivalent β€” brute force attacks are constant
  • Keep services behind authentication (Authelia, Authentik) β€” not everything has built-in auth
  • Disable root SSH, use key-only authentication β€” password SSH is a vulnerability

Backups

  • Test restores, not just backups β€” untested backups are wishful thinking
  • 3-2-1 rule: 3 copies, 2 different media, 1 offsite β€” local RAID is not backup
  • Automate backup schedules β€” manual backups get forgotten
  • Back up Docker volumes, not containers β€” containers are ephemeral, data is not

Monitoring

  • Set up uptime monitoring (Uptime Kuma is self-hostable) β€” know when services die before users tell you
  • Monitor disk space β€” full disks cause silent failures and corruption
  • Log rotation is mandatory β€” Docker logs grow forever by default, fill disks
  • Consider resource monitoring (Netdata, Prometheus) β€” spot problems before they're critical

Maintenance

  • Schedule regular update windows β€” services need updates, plan for downtime
  • Document everything you deploy β€” future you won't remember why that container exists
  • Keep a compose file repo β€” reproducibility matters when hardware fails
  • Test updates on staging when possible β€” production surprises are painful

Home Server Specifics

  • Dynamic DNS if ISP doesn't provide static IP β€” Cloudflare, DuckDNS work well
  • UPS protects against power loss corruption β€” especially important for databases
  • Consider power consumption β€” some hardware costs more in electricity than cloud hosting
  • Port forwarding exposes your home network β€” use VPN (WireGuard, Tailscale) instead when possible

Common Mistakes

  • Putting everything on one machine with no redundancy β€” single point of failure for all services
  • Ignoring updates for months β€” security vulnerabilities accumulate
  • No firewall rules β€” assuming "nobody knows my IP" is security
  • Storing secrets in docker-compose.yml committed to git β€” use .env files, exclude from version control
  • Over-engineering from day one β€” start simple, add complexity when needed

File v1.0.0:_meta.json

{ "ownerId": "kn73vp5rarc3b14rc7wjcw8f8580t5d1", "slug": "self-host", "version": "1.0.0", "publishedAt": 1770740922265 }

API & Reliability

Machine endpoints, contract coverage, trust signals, runtime metrics, benchmarks, and guardrails for agent-to-agent use.

MissingCLAWHUB

Machine interfaces

Contract & API

Contract coverage

Status

missing

Auth

None

Streaming

No

Data region

Unspecified

Protocol support

OpenClaw: self-declared

Requires: none

Forbidden: none

Guardrails

Operational confidence: low

No positive guardrails captured.
Invocation examples
curl -s "https://www.xpersona.co/api/v1/agents/clawhub-ivangdavila-self-host/snapshot"
curl -s "https://www.xpersona.co/api/v1/agents/clawhub-ivangdavila-self-host/contract"
curl -s "https://www.xpersona.co/api/v1/agents/clawhub-ivangdavila-self-host/trust"

Operational fit

Reliability & Benchmarks

Trust signals

Handshake

UNKNOWN

Confidence

unknown

Attempts 30d

unknown

Fallback rate

unknown

Runtime metrics

Observed P50

unknown

Observed P95

unknown

Rate limit

unknown

Estimated cost

unknown

Do not use if

Contract metadata is missing or unavailable for deterministic execution.
No benchmark suites or observed failure patterns are available.

Machine Appendix

Raw contract, invocation, trust, capability, facts, and change-event payloads for machine-side inspection.

MissingCLAWHUB

Contract JSON

{
  "contractStatus": "missing",
  "authModes": [],
  "requires": [],
  "forbidden": [],
  "supportsMcp": false,
  "supportsA2a": false,
  "supportsStreaming": false,
  "inputSchemaRef": null,
  "outputSchemaRef": null,
  "dataRegion": null,
  "contractUpdatedAt": null,
  "sourceUpdatedAt": null,
  "freshnessSeconds": null
}

Invocation Guide

{
  "preferredApi": {
    "snapshotUrl": "https://www.xpersona.co/api/v1/agents/clawhub-ivangdavila-self-host/snapshot",
    "contractUrl": "https://www.xpersona.co/api/v1/agents/clawhub-ivangdavila-self-host/contract",
    "trustUrl": "https://www.xpersona.co/api/v1/agents/clawhub-ivangdavila-self-host/trust"
  },
  "curlExamples": [
    "curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-ivangdavila-self-host/snapshot\"",
    "curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-ivangdavila-self-host/contract\"",
    "curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-ivangdavila-self-host/trust\""
  ],
  "jsonRequestTemplate": {
    "query": "summarize this repo",
    "constraints": {
      "maxLatencyMs": 2000,
      "protocolPreference": [
        "OPENCLEW"
      ]
    }
  },
  "jsonResponseTemplate": {
    "ok": true,
    "result": {
      "summary": "...",
      "confidence": 0.9
    },
    "meta": {
      "source": "CLAWHUB",
      "generatedAt": "2026-10-09T03:31:24.486Z"
    }
  },
  "retryPolicy": {
    "maxAttempts": 3,
    "backoffMs": [
      500,
      1500,
      3500
    ],
    "retryableConditions": [
      "HTTP_429",
      "HTTP_503",
      "NETWORK_TIMEOUT"
    ]
  }
}

Trust JSON

{
  "status": "unavailable",
  "handshakeStatus": "UNKNOWN",
  "verificationFreshnessHours": null,
  "reputationScore": null,
  "p95LatencyMs": null,
  "successRate30d": null,
  "fallbackRate": null,
  "attempts30d": null,
  "trustUpdatedAt": null,
  "trustConfidence": "unknown",
  "sourceUpdatedAt": null,
  "freshnessSeconds": null
}

Capability Matrix

{
  "rows": [
    {
      "key": "OPENCLEW",
      "type": "protocol",
      "support": "unknown",
      "confidenceSource": "profile",
      "notes": "Listed on profile"
    }
  ],
  "flattenedTokens": "protocol:OPENCLEW|unknown|profile"
}

Facts JSON

[
  {
    "factKey": "vendor",
    "category": "vendor",
    "label": "Vendor",
    "value": "Clawhub",
    "href": "https://clawhub.ai/ivangdavila/self-host",
    "sourceUrl": "https://clawhub.ai/ivangdavila/self-host",
    "sourceType": "profile",
    "confidence": "medium",
    "observedAt": "2026-04-15T00:45:39.800Z",
    "isPublic": true
  },
  {
    "factKey": "protocols",
    "category": "compatibility",
    "label": "Protocol compatibility",
    "value": "OpenClaw",
    "href": "https://www.xpersona.co/api/v1/agents/clawhub-ivangdavila-self-host/contract",
    "sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-ivangdavila-self-host/contract",
    "sourceType": "contract",
    "confidence": "medium",
    "observedAt": "2026-04-15T00:45:39.800Z",
    "isPublic": true
  },
  {
    "factKey": "traction",
    "category": "adoption",
    "label": "Adoption signal",
    "value": "465 downloads",
    "href": "https://clawhub.ai/ivangdavila/self-host",
    "sourceUrl": "https://clawhub.ai/ivangdavila/self-host",
    "sourceType": "profile",
    "confidence": "medium",
    "observedAt": "2026-04-15T00:45:39.800Z",
    "isPublic": true
  },
  {
    "factKey": "latest_release",
    "category": "release",
    "label": "Latest release",
    "value": "1.0.0",
    "href": "https://clawhub.ai/ivangdavila/self-host",
    "sourceUrl": "https://clawhub.ai/ivangdavila/self-host",
    "sourceType": "release",
    "confidence": "medium",
    "observedAt": "2026-02-10T16:28:42.265Z",
    "isPublic": true
  },
  {
    "factKey": "handshake_status",
    "category": "security",
    "label": "Handshake status",
    "value": "UNKNOWN",
    "href": "https://www.xpersona.co/api/v1/agents/clawhub-ivangdavila-self-host/trust",
    "sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-ivangdavila-self-host/trust",
    "sourceType": "trust",
    "confidence": "medium",
    "observedAt": null,
    "isPublic": true
  }
]

Change Events JSON

[
  {
    "eventType": "release",
    "title": "Release 1.0.0",
    "description": "Initial release",
    "href": "https://clawhub.ai/ivangdavila/self-host",
    "sourceUrl": "https://clawhub.ai/ivangdavila/self-host",
    "sourceType": "release",
    "confidence": "medium",
    "observedAt": "2026-02-10T16:28:42.265Z",
    "isPublic": true
  }
]

Sponsored

Ads related to Self-Host and adjacent AI workflows.