OpenClaw AI Agent - Hardened Ubuntu AMI
Software Sushi · Cybersecurity & IT
Certification per AWS Marketplace.
Evidence tier Source Confirmed · 4 captures on record
What the publisher says
As described on AWS Marketplace.
OpenClaw is an AI agent framework that turns an EC2 instance into a personal AI assistant. Connect it to the channels your users are already on and the AI providers you prefer. This AMI gives you a hardened, production-ready foundation. Add your credentials, configure your channels, and your agent is live. Your data stays on your instance, your keys stay in your account, and you control the infrastructure.
Channels: Telegram, Slack, Discord, WhatsApp, web, and more. Connect one or many. OpenClaw handles routing, conversation state, and memory across all of them.
Show the rest of the publisher’s description (19 more lines)
AI providers: OpenAI, Anthropic, AWS Bedrock, Google Vertex AI, OpenRouter, and more. Bring your own keys, no vendor lock-in, no per-message fees from us.
What's pre-installed:
- Ubuntu 24.04 LTS (Canonical official base)
- Node.js v22 (LTS) via NodeSource
- OpenClaw AI agent framework
- 4 GB swap file (prevents OOM on smaller instances)
- Complete directory structure ready for configuration
Security hardening included:
- UFW firewall: default deny inbound, SSH (22) and gateway port (18789) allowed
- Fail2ban: bans IPs after 5 failed SSH attempts (1-hour ban)
- SSH hardened: key-only authentication, no password login, no X11, max 3 auth tries
- Kernel hardening: ICMP redirects disabled, IP forwarding disabled
- Unattended upgrades: daily automatic security patches (no auto-reboot)
- Log rotation: daily rotation with 7-day retention for OpenClaw logs
Getting started after launch:
- SSH in as the ubuntu user: ssh -i your-key.pem ubuntu@<public-ip>
- Run: openclaw onboard
- Follow the onboard wizard to configure your AI provider, channels, and agent settings
Recommended instance type: t3.medium (2 vCPU, 4 GB RAM) or larger. Root volume: 20 GB gp3 (default).
Highlights
Highlighted by the publisher on AWS Marketplace.
Ready in minutes: SSH in, run "openclaw onboard", and follow the wizard. OpenClaw, Node.js v22, swap, firewall, and log rotation are all pre-configured. No manual config files needed, the onboard wizard walks you through AI provider, channels, and agent setup.
Security-hardened from the start: UFW firewall with default-deny policy, fail2ban SSH brute-force protection, key-only SSH authentication, kernel-level network hardening. No additional configuration needed. Hardening is baked into the AMI and active on first boot.
Works with your stack: connect to OpenAI, Anthropic, AWS Bedrock, Google Vertex AI, OpenRouter, or any compatible provider. Reach users on Telegram, Slack, Discord, WhatsApp, and more. Bring your own keys, no vendor lock-in, no per-message fees from us.
Agent build and provenance
See the full provenance
The layer-by-layer build, the evidence behind each claim, the risk basis and the cross-marketplace links are open to any account. Some rows are disclosed, some the source leaves Unknown; a free account shows you which.
Refund terms
As stated by the publisher on AWS Marketplace.
We offer a full refund of software charges for the first 48 hours billing starts if the product does not perform as described. To request a refund, email info@softwaresushi.com with your EC2 instance ID and a description of the issue. AWS infrastructure costs (EC2, EBS, data transfer) are billed by AWS and are not eligible for refund by us.
Sources
Linked repositories
1 repoUnknown means this listing does not publish a repository. It is not a statement that the code is closed, and a linked repository is not a claim that the publisher wrote it: the registry computes that relationship privately and does not publish it.
Evidence risk is the share of the build you cannot see before you deploy, not a security rating. Sign in to see the layer-by-layer basis for this band.

