Why it matters

The reverse proxy handles HTTPS, routing, and the public face of the service so the underlying gateway can stay private and simple.

Checklist

  • Bind OpenClaw to localhost
  • Expose only 80/443 publicly
  • Terminate TLS at Caddy or Nginx
  • Confirm headers and upstream target are correct

Mistakes to avoid

  • Leaving the raw gateway port public
  • Skipping HTTP to HTTPS redirects
  • Assuming local bind and public bind are the same thing

Next step

Once the proxy is in place, finish with firewall and service hardening.