Sign inSign up

docker/sbx-kit-openclaw-mixin:latest

Multi-platform
Manifest digest

sha256:5fe0135fabd7075ff6e2da26d14138d354c729a275286b8c44bb962ae1da5c18

Last pushed

9 days by cdupuis

Type

Sandbox Kit

Manifest digest

sha256:5fe0135fabd7075ff6e2da26d14138d354c729a275286b8c44bb962ae1da5c18

yaml
schemaVersion: "3"
displayName: OpenClaw (mixin)
description: OpenClaw as a mixin -- Node, the pinned openclaw release and the Chromium the browser tool uses, in an overlay, with the Anthropic credential (API key or claude.ai OAuth), the published gateway port and the gateway bootstrap hook. Layer it onto a shell base and run `openclaw`.
sourceUrl: https://github.com/openclaw/openclaw
kind: mixin
provides:
    - [email protected]
requires:
    - deb/docker-ce
capabilities:
    - type: com.docker.sandbox/network-policy@1
      config:
        runtime:
            allow:
                - api.anthropic.com
                - claude.ai
                - console.anthropic.com
                - openrouter.ai
                - auth.docker.io
                - production.cloudfront.docker.com
                - registry-1.docker.io
                - registry.npmjs.org
                - '*.npmjs.org'
                - clawhub.ai
                - raw.githubusercontent.com
                - '*.telegram.org'
                - '*.discord.com'
                - gateway.discord.gg
                - '*.whatsapp.com'
                - '*.whatsapp.net'
                - '*.slack.com'
                - platform.claude.com
                - openclaw.ai
                - docs.openclaw.ai
    - type: com.docker.sandbox/port@1
      config:
        container: 18789
        name: gateway
    - type: com.docker.sandbox/credential@1
      optional: true
      config:
        apiKey:
            inject:
                - domain: api.anthropic.com
                  format: '%s'
                  header: x-api-key
                - domain: claude.ai
                  format: '%s'
                  header: x-api-key
                - domain: console.anthropic.com
                  format: '%s'
                  header: x-api-key
            name: ANTHROPIC_API_KEY
            proxyManaged: true
        oauth:
            credentialFile:
                path: ~/.claude/.credentials.json
                structure:
                    claudeAiOauth:
                        accessToken: '{{.AccessToken}}'
                        expiresAt: '{{.ExpiresAt}}'
                        refreshToken: '{{.RefreshToken}}'
                        scopes: '{{.Scopes}}'
            resourceHosts:
                - api.anthropic.com
            sentinels:
                accessToken: sk-ant-oat01-proxy-managed
                refreshToken: sk-ant-ort01-proxy-managed
            tokenEndpoint:
                host: platform.claude.com
                path: /v1/oauth/token
        phase: runtime
        service: anthropic
      description: Anthropic API access (API key or claude.ai OAuth)
    - type: com.docker.sandbox/lifecycle@1
      config:
        startup:
            - command:
                - sh
                - /home/agent/.local/bin/openclaw-gateway-up.sh
              description: Start the OpenClaw gateway so the published port and CLI work without attaching the TUI
              env:
                - OPENCLAW_STATE_DIR
                - OPENCLAW_GATEWAY_PORT
                - SBX_CRED_ANTHROPIC_MODE
                - DOCKER_HOST
              user: "1000"
    - type: com.docker.sandbox/agent-context@1
      config:
        contentFile: /usr/share/sandbox/kit/openclaw-mixin/openclaw-mixin-context.md
args:
    version:
        default: 2026.9.3
        description: OpenClaw release to install
        pattern: ^[0-9]+\.[0-9]+\.[0-9]+$
        buildArg: OPENCLAW_VERSION