Acceptance checklist
- Ubuntu version and initial package state recorded
- Dedicated non-sudo service user and pinned OpenClaw version verified
- systemd enable, restart, health, and failure behavior captured
- SSH key-only access proven before password authentication is disabled
- UFW and fail2ban state captured; only agreed public ports exposed
- Every non-SSH service verified as loopback-bound unless explicitly approved
- Secrets stored in mode-0600 environment files and absent from unit files, logs, and shell history
- Monitoring, log access, recovery steps, and rollback notes tested
- Telegram connectivity checked with redacted output when included in scope
- Runbook and secret-free screen recording delivered
Example evidence index
Outputs are redacted before delivery. Secret values are never copied into this index.
Telegram photo → exact job record
A production attachment path should never guess the destination from the image alone. The sample contract requires an explicit job key, validates that exactly one job matches, and uses telegramUpdateId:telegramFileUniqueId as the replay key before any attachment write.
The downloadable sample uses synthetic identifiers only. It is not a customer implementation and does not include photo bytes, tokens, staff identity, chat history, or production records.
Download sample contractDownload verifierRuntime model
OpenClaw runs as a managed service on the new VPS. The buyer can operate it from a local machine and, when included, through Telegram. The VPS remains the runtime, so the local operator machine does not need to stay online.
Start with the beginner safety check — $69 →