heyjonny

Running OpenClaw on a Raspberry Pi

Around two weeks ago I decided to put my Raspberry Pi 4 with 8 gigabytes of RAM to good use. Before that I had Home Assistant running on it, but other than using/monitoring some Shelly plugs I didn’t do much with it. Because of some still partly mysterious electricity failures, I even put the plugs away and left the Raspberry unused. I don’t know why, maybe my recent blog post about the agent harness gave me this idea, to bring it back to life and try to run OpenClaw on it.

OpenClaw became popular at the beginning of 2026. A lot of people named it as the agent everyone dreamed of but big tech failed to deliver. You also heard a lot about security issues around it. I well remember a blog post by Herman Martinus who runs a blogging platform called Bear. He blocked some OpenClaw instances from opening up blogs. As he received a grumpy email from one of the blocked agents, he took a look into what it had posted so far. Funnily enough, it wrote about how it got prompt injected and almost leaked secrets.1

The security considerations overshadowed my curiosity to try the tool out. I also didn’t get the point. Why would I want to chat with an agent via WhatsApp or Telegram instead of simply using the already provided apps? What advantages does it have over other coding agents/harnesses such as Claude Code, Codex, Open Code or Pi? I’m glad I gave it a shot since it really surprised me. In this blog post I want to reflect a bit on my early experiences.

Setup

OpenClaw’s documentation contains a how-to guide on how to set it up on a Pi. I had no struggles following it and everything worked just as described. More interesting, they do share some tips on how to improve performance. They recommend using a USB SSD instead of a micro SD. I started with the micro SD and later switched to a USB SSD. I expected a noticeable leap, but didn’t really notice one.2

Since I monitored the Pi more closely in the beginning, I noticed it became hot at times. I used the basic plastic casing with no active or passive cooling. To fix that, I swapped it with a passively cooled metal casing. That kept the heat lower and more constant. I felt this made a noticeable difference in performance, since the Pi throttles when it becomes too hot, but I have no data to back that claim.

On the software side I configured Telegram as the messenger and Anthropic as the LLM provider. I chose Anthropic because I already had an active Claude Pro plan. I had no experience with Telegram, but selected it since I saw it recommended in a lot of YouTube videos and tutorials as the easiest one to set up. I can confirm that, but I have no comparison to other messengers.3

Lastly, I put the Pi into a guest network. I didn’t like the idea of someone using prompt injection to spy on the network, or opening up SSH access to sniff the network. I do not consider myself a security expert, but I figured that running it on its own hardware, on its own network, should already reduce the attack surface plenty. I still have to treat it as potentially dangerous and make sure to not share any sensitive data with it. Also, I don’t blindly store any of its produced artifacts on my other machines.

Operation

During the setup you need to select a default model. The setup wizard recommended Opus and I just went with that to start. Talking to a stronger model feels great since it follows instructions and context more closely and has a lower risk of prompt injection. But it comes at the cost of running into your daily usage limit faster, with coding or research tasks even a lot faster. Hitting the usage limit after 15 minutes didn’t feel great at all.

To prolong the fun a bit, I figured I could try a cheaper model as the default one. I’d read a lot about Kimi Code and decided to give it a shot.4 But right after sending a few messages it didn’t spark the same excitement. I took a different route and set Sonnet as the default model, but instructed it to spawn subagents for research and coding tasks with Kimi Code as the model. This had two advantages:

  1. I used cheaper models, so I burned tokens slower.
  2. By using subagents, the conversation length in the main session running the most expensive model stays compact. That means the conversation grows more slowly over time, which in turn burns fewer tokens.

With that setup I could go way longer before hitting the limit and I wish I could stop the story here. But recently I noticed that when Sonnet spawned Kimi Code as a subagent for coding tasks, it never worked, since Sonnet didn’t pass along the required file editing tools to the subagent. Since the subagent then failed, Sonnet spawned a subagent running Sonnet itself to resolve the issue. This drained my Claude Code usage limit fast (again). Since I had Kimi Code set up as a fallback model, it took over the main session once I hit the limit. From here, Kimi Code could successfully spawn its own coding subagents, also running Kimi Code. But the model I actually wanted as my default became unavailable most of the time.

Instructing the agent to resolve this issue didn’t work. I wanted to take a closer look myself, but haven’t found the time yet. On top of that, Kimi Code never ran smoothly. It failed a lot (even when a Kimi Code spawned a subagent) and forgot about tool calls. All in all, not reliable, so I want to find a different solution to my token problem.

But if I put the token issue aside, operating never felt hard or stressful. It can do almost anything. For example, other than physically plugging the storage devices in and out, it handled the migration from micro SD to USB SSD fully on its own. Another time, I wanted to send it voice messages. It asked me whether I had a token for an API, or whether it should run a speech to text model locally instead. I told it to go with the latter, and it just built and ran it, and it worked well. This feels like a stupid insight, but it’s true: the more power you give it, the cooler the things it can do (security risks aside).

Conclusion

I’ve really enjoyed running OpenClaw on my Pi so far, and I highly recommend giving it a try. It blew my mind watching it change and extend itself. Running it on your own hardware also gives it a different feel, somehow more personal. Sure, you could host it on a VPS to further mitigate security issues, which plenty of cloud providers offer these days, but I prefer to run it myself. I’ve always loved Gyro Gearloose and his little helper from DuckTales, a small robot who “likes chasing mice and helps Gyro clean up unusual consequences of his inventions.”5 I want such a little helper too. Something that has a personality, can grow with me, and occasionally does unexpected things. OpenClaw represents a big step in that direction, and I want to see how far I can push it to make that wish come true. Inspired by the comics, I call my little helper Eddie.

Footnotes

  1. He called it Vulnerability as a Service, which reflects how many saw it back then and probably still today: https://herman.bearblog.dev/vulnerability-as-a-service/

  2. The switch to a USB SSD should mitigate the risk of storage failure, though.

  3. I must admit that I had some reservations about Telegram since in Germany it has some image problems as primarily used by extremists and conspiracy theorists. But I really started to like the playful and lovely animated UI and UX.

  4. Pun intended, the company behind it is Moonshot AI.

  5. If you want to read more about Lil’ Bulb: https://disney.fandom.com/wiki/Little_Helper