--profile <name> flag (named AWS CLI profile).env.aws file in workspace root or skill directory (optional):
AWS_ACCESS_KEY_ID=...
AWS_SECRET_ACCESS_KEY=...
AWS_DEFAULT_REGION=us-east-1.env.starfish in workspace root (recommended) or skill directory:
TELEGRAM_BOT_TOKEN=... # from @BotFather (required)
TELEGRAM_USER_ID=... # your Telegram user ID (optional, enables auto-approve pairing)
GEMINI_API_KEY=... # from aistudio.google.com (optional, for Gemini models)aws CLI installed OR Docker for sandboxed accessjq, openssl available# From the skill directory:
./scripts/deploy_minimal.sh --name starfish --region us-east-1 \
--env-dir /path/to/workspace
# Or with cleanup of previous deployment first:
./scripts/deploy_minimal.sh --name starfish --region us-east-1 \
--env-dir /path/to/workspace --cleanup-first
This single command:
deploy-output.jsonaws ssm start-session --target <INSTANCE_ID> --region us-east-1
sudo -u openclaw bash
export HOME=/home/openclaw
openclaw pairing approve telegram <CODE># Using saved output:
./scripts/teardown.sh --from-output ./deploy-output.json --env-dir /path/to/workspace --yes
# Or by name (discovers via tags):
./scripts/teardown.sh --name starfish --region us-east-1 --env-dir /path/to/workspace --yes
--model flagPass any model string — it goes directly into openclaw.json as model.primary:
# Default (MiniMax M2.1 on Bedrock — no API key needed, uses IAM role)
./scripts/deploy_minimal.sh --name starfish --region us-east-1
# Gemini Flash (needs GEMINI_API_KEY in .env.starfish)
./scripts/deploy_minimal.sh --name starfish --region us-east-1 \
--model google/gemini-2.0-flash
Bedrock IAM permissions (bedrock:InvokeModel, bedrock:InvokeModelWithResponseStream) are always added to the instance role — regardless of which model you choose. This means any deployed instance can use Bedrock models out of the box via IAM role credentials (no API key needed).
| Known Bedrock model IDs: | Model flag | Description |
|---|---|---|
amazon-bedrock/minimax.minimax-m2.1 |
MiniMax M2.1 | |
amazon-bedrock/minimax.minimax-m2 |
MiniMax M2 | |
amazon-bedrock/deepseek.deepseek-r1 |
DeepSeek R1 | |
amazon-bedrock/moonshotai.kimi-k2.5 |
Kimi K2.5 |
Note: Bedrock models must be enabled in your AWS account via the Bedrock console before use.
If GEMINI_API_KEY is present in .env.starfish, it's stored in SSM and written to auth-profiles.json. If absent, it's simply skipped — no error.
.env.starfishTELEGRAM_BOT_TOKEN=... # Required — from @BotFather
GEMINI_API_KEY=... # Optional — from aistudio.google.com (needed for Gemini models)
┌─────────────────────────────────────────────────────┐
│ VPC (10.50.0.0/16) │
│ ┌───────────────────────────────────────────────┐ │
│ │ Public Subnet (10.50.0.0/24) │ │
│ │ ┌─────────────────────────────────────────┐ │ │
│ │ │ EC2 t4g.medium (ARM64, 4GB) │ │ │
│ │ │ ┌───────────────────────────────────┐ │ │ │
│ │ │ │ OpenClaw Gateway │ │ │ │
│ │ │ │ • Node.js 22.14.0 │ │ │ │
│ │ │ │ • Any model (Bedrock/Gemini/etc) │ │ │ │
│ │ │ │ • Telegram channel │ │ │ │
│ │ │ │ • Encrypted EBS (gp3, 20GB) │ │ │ │
│ │ │ └───────────────────────────────────┘ │ │ │
│ │ └─────────────────────────────────────────┘ │ │
│ └───────────────────────────────────────────────┘ │
└─────────────────────────────────────────────────────┘
↑ ↓
SSM (no SSH/inbound) Outbound HTTPS only
These are baked into the deploy script. See references/TROUBLESHOOTING.md for full details.
openclaw@latest — bare openclaw may resolve to placeholder package (0.0.1)openclaw gateway run --allow-unconfigured — NOT gateway start (which tries systemctl --user and fails)7w4.net收錄了海量優質技能外掛。
openclaw.json — not config.yamlgateway.mode: "local" — required or you get "Missing config" errorgateway.auth.mode: "token" — "none" is invalidplugins.entries.telegram.enabled: true — must be explicitdmPolicy: "pairing" — not "allowlist" (blocks everyone without user list)streamMode: "partial" — some models don't support streaming tools, use "off" as fallbackauth-profiles.json in agent diramazon-bedrock/MODEL_ID (not bedrock/)ProtectHome, ReadWritePaths=/tmp/openclaw, PrivateTmp due to namespace issuesNODE_OPTIONS="--max-old-space-size=1024" — helps prevent OOMHttpTokens=requiredscripts/
deploy_minimal.sh # One-shot deploy (VPC + EC2 + OpenClaw)
teardown.sh # Clean teardown of all resources
setup_deployer_role.sh # Create IAM role/user with minimum permissions
preflight.sh # Pre-deploy validation checks
smoke_test.sh # Post-deploy health verification
references/
TROUBLESHOOTING.md # All 22 issues + solutions
config-templates/ # Ready-to-use config files
gemini-flash.json # OpenClaw config for Gemini Flash
auth-profiles-gemini.json # Auth profile template
openclaw.service.txt # Systemd unit file template
startup.sh # Startup script template
See references/config-templates/gemini-flash.json — includes all required fields.
Create at ~/.openclaw/agents/main/agent/auth-profiles.json
Simplified for reliability — security hardening removed due to namespace issues.
| Resource | Cost |
|---|---|
| t4g.medium (4GB ARM64) | ~$24.53/mo |
| EBS gp3 20GB | ~$1.60/mo |
| Public IP | ~$3.65/mo |
| Gemini Flash | Free tier / ~$0.30/1M tokens |
| Total | ~$29.78/mo |
Cause: OpenClaw needs models.providers config in openclaw.json with "auth": "aws-sdk". An auth-profiles.json entry alone is NOT sufficient.
Fix: Add to openclaw.json on the instance:
sudo -u openclaw bash
cd /home/openclaw/.openclaw
jq '.models = {
"providers": {"amazon-bedrock": {"baseUrl": "https://bedrock-runtime.us-east-1.amazonaws.com", "api": "bedrock-converse-stream", "auth": "aws-sdk", "models": [{"id": "minimax.minimax-m2.1", "name": "MiniMax M2.1", "input": ["text"], "contextWindow": 128000, "maxTokens": 4096}]}},
"bedrockDiscovery": {"enabled": true, "region": "us-east-1"}
}' openclaw.json > /tmp/oc.json && mv /tmp/oc.json openclaw.json
chown openclaw:openclaw openclaw.json
systemctl restart openclaw
Fix: Switch to Bedrock (default in current version) or redeploy with --model amazon-bedrock/minimax.minimax-m2.1.
Cause: Model must be enabled in AWS Console → Bedrock → Model access. MiniMax models are auto-authorized; Anthropic/Meta models require use-case approval.
Fix: Add TELEGRAM_USER_ID to .env.starfish for auto-pairing, or use --pair-user <id>. Manual: openclaw pairing approve telegram <CODE> via SSM.
Project=<name> and DeployId=<unique-id> for deterministic cleanup質量很好,文件詳細、使用說明清晰。優勢是安全性高(無 SSH、直接通過訊息控制)、支援多種 AI 模型、人格可定製。部署成功後基本無需額外維護。不足是需要一定的技術基礎,依賴 AWS 環境。總體推薦,適合需要自動化部署 AI agent 的使用者。