feat(openclaw): set the startup env doctor recommends on ARM hosts

Add NODE_COMPILE_CACHE and OPENCLAW_NO_RESPAWN, and record the remaining
doctor notes and the ARM64 browser path override in docs/openclaw.
This commit is contained in:
tiennm99 committed 2026-10-05 16:33:27 +07:00
1 parent 0a7e8f9783
commit d4256617f4
3 files changed
+47

No files matched your search

+39
View File
@@ -0,0 +1,39 @@
# openclaw doctor findings
State of `openclaw doctor` on the miti-sg deployment after the migration from
the old Temp service, as of release 2026.9.8.
## Live-config workaround to undo
On ARM64, 2026.9.8 looks for the image's Playwright Chromium only under
`chrome-linux64/` and `chrome-linux/`, but the ARM64 build lives in
`chrome-linux-arm64/`. Upstream `main` already searches that directory
(`extensions/browser/src/browser/chrome.executables.ts`). Until a release
carries it, the live config points at the binary directly:
```
browser.executablePath = /home/node/.cache/ms-playwright/chromium-1243/chrome-linux-arm64/chrome
```
The path names the Playwright build (`chromium-1243`), so it breaks when an
image update ships a newer Chromium, and doctor will report the browser as
missing again. Once a release auto-detects the ARM64 build, remove the
override:
```sh
node openclaw.mjs config unset browser.executablePath
```
The same session also set `browser.headless=true` and
`browser.noSandbox=true`. Chromium aborts inside this container with its
sandbox enabled, and the container has no display. These two stay.
## Notes that remain, by design
| Note | Why it stays |
| --- | --- |
| Session SQLite: 31 deferred historical transcripts | Daily 03:00 cron runs from May–June 2026 (one prompt, one reply each) plus one probe, whose header ID differs from the file name. Upstream: no action needed when expected conversations are present; do not edit receipts to silence it. |
| Gateway: service management skipped | Docker supervises the process, not OpenClaw. |
| Host desktop: disabled | Optional desktop lab, not used. |
| Security: bound to `lan` | Required in a container behind Coolify's proxy; auth is the gateway token. Fires for any non-loopback bind. |
| GitHub projects | Optional; set `gateway.controlUi.github.token` only if private-repo search is wanted. |
+6
View File
@@ -42,6 +42,12 @@ the token is what keeps the Control UI and API closed. Provider and channel
keys are read from the environment, so the provider set is changed by
uncommenting lines.
`NODE_COMPILE_CACHE` and `OPENCLAW_NO_RESPAWN=1` are the values `doctor`
recommends on ARM and small Linux hosts: a compile cache that speeds up
repeated CLI runs, and gateway restarts that stay inside the process instead
of handing off to a supervisor, since Docker's restart policy already
supervises the container.
`OPENCLAW_TRUSTED_PROXIES` must cover the address Coolify's Traefik connects
from. Traefik joins each app's network with an address from the Docker
address pool, which on this host is `10.0.0.0/16` in `/24` slices; the gateway
+2
View File
@@ -16,6 +16,8 @@ services:
- OPENCLAW_WORKSPACE_DIR=/home/node/.openclaw/workspace
- OPENCLAW_GATEWAY_PORT=18789
- TERM=xterm-256color
- NODE_COMPILE_CACHE=/var/tmp/openclaw-compile-cache
- OPENCLAW_NO_RESPAWN=1
- OPENROUTER_API_KEY=${OPENROUTER_API_KEY:-}
- TZ=${TZ:-Asia/Ho_Chi_Minh}
# - ANTHROPIC_API_KEY=${ANTHROPIC_API_KEY:-}