ov-openclaw/skills/openclaw/SKILL.md
Headless OpenClaw AI gateway image. Runs the gateway on port 18789 without a desktop environment. Use when working with the headless MUST be invoked before building, deploying, configuring, or troubleshooting the openclaw image.
npx skillsauth add overthinkos/overthink-plugins openclawInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
Headless OpenClaw AI gateway — no desktop, no browser, just the gateway service.
| Property | Value | |----------|-------| | Base | fedora | | Layers | agent-forwarding, openclaw | | Platforms | linux/amd64 | | Ports | 18789 | | Registry | ghcr.io/overthinkos |
fedora (quay.io/fedora/fedora:43)pixi → python → supervisord (transitive)nodejs (transitive via openclaw)openclaw — gateway on :18789, data volume| Port | Service | Protocol | |------|---------|----------| | 18789 | OpenClaw gateway + Control UI | HTTP |
ov image build openclaw
ov config openclaw
ov start openclaw
# Gateway at http://localhost:18789
/ov-openclaw:openclaw — gateway npm package, supervisord service, data volume/ov-openclaw:openclaw-sway-browser — adds desktop + Chrome for browser automation/ov-openclaw:openclaw-ollama — adds local LLM inference/ov-openclaw:openclaw-ollama-sway-browser — full stack with desktop + LLMAfter ov start:
ov status openclaw — container runningov service status openclaw — all services RUNNINGcurl -s http://localhost:18789 — OpenClaw gateway respondsOpenClaw gateway (18789) uses port relay (socat) — the gateway binds to loopback, socat forwards from the container interface. This avoids the allowedOrigins requirement for the Control UI.
MUST be invoked when the task involves the headless openclaw image, deploying openclaw without a desktop, or comparing openclaw variants. Invoke this skill BEFORE reading source code or launching Explore agents.
/ov-build:image — image family umbrella (image: entries in overthink.yml, build/validate/inspect/list)/ov-build:build — build.yml vocabulary (distros, builders, init-systems)tools
Use when authoring or modifying a charly PLUGIN — a candy with a `plugin:` block that contributes Providers (verbs/kinds/deploy-targets/steps/builders/commands), its own CUE schema, builtin (compiled-in) or external (out-of-tree git repo). Covers the unified Provider model, the per-plugin CUE-schema contract (single source → Go params for dev + schema-over-Describe RPC for runtime), the SDK, and the loader.
tools
The CUE data-validation / configuration CLI (cue), pinned to v0.16.1. Use when working with the cue candy, installing the cue binary into a box or onto a target:local dev host, or running the offline schema-vendoring pipeline that feeds charly's egress validation.
tools
CUE EGRESS validation — validating (and, where it adds value, generating) the config files charly WRITES to a system BEFORE the bytes hit disk. MUST be invoked before working on charly/egress.go, the vendored schemas under candy/plugin-egress/egress-schemas/vendor/, the ValidateEgress / registerVendoredEgressKind path, the offline `task cue:vendor` pipeline, or adding an egress schema for any written artifact (cloud-init, k8s manifests, traefik routes, runtime config, install ledger, systemd/quadlet units, ssh_config, libvirt XML).
tools
Kubernetes cluster-probe declarative check verb — the `kube:` check verb (nodes, pods, ingress, storage class, addon health, apply/delete, and arbitrary resource GETs) served out-of-process by the candy/plugin-kube plugin (vendored client-go; no external kubectl required).