Why it matters
The reverse proxy handles HTTPS, routing, and the public face of the service so the underlying gateway can stay private and simple.
Checklist
- Bind OpenClaw to localhost
- Expose only 80/443 publicly
- Terminate TLS at Caddy or Nginx
- Confirm headers and upstream target are correct
Mistakes to avoid
- Leaving the raw gateway port public
- Skipping HTTP to HTTPS redirects
- Assuming local bind and public bind are the same thing
Next step
Once the proxy is in place, finish with firewall and service hardening.