AIAI EngineerMay 22, 2026· 21:56

Lobster Trap: OpenClaw in Containers from Local to K8s and Back — Sally Ann O'Malley, Red Hat

Sally Ann O'Malley of Red Hat argues that running OpenClaw in containers with Podman and Kubernetes delivers secure, portable, and reproducible AI agent setups. She uses Podman secrets and OpenClaw's secret ref feature to manage API keys, ensuring secrets stay out of logs and configs. O'Malley demonstrates a local installer that spins up an OpenClaw container in two seconds and lifts the same workload to Kubernetes. She cites an Nvidia team of 10 engineers each running their own OpenClaw in Kubernetes for model evals, claiming it replaced the work of six people. Her vision is a team-standard containerized OpenClaw baseline with company-approved MCP servers and skills, enabling reproducible onboarding and personalization across an organization.

  1. 0:00Intro
  2. 1:25Discovery
  3. 3:05Forever Claw
  4. 5:52Config & Secrets
  5. 8:10Scaling & Nvidia
  6. 11:09Backup & Vision
  7. 14:14Live Demo
  8. 20:52Kubernetes

Powered by PodHood

Transcript

Intro0:00

Sally Ann O'Malley0:15

Hey, um, I'm Sally. I work at Red Hat. I've been there for about 10 years, and the first 7 years— Awesome. Totally cool. I was working on containers and, uh, Linux security stuff, and Kubernetes. I'm big time in OpenShift, that's what I did for the first 7 years.

And then, uh, about 3 years ago—well, about 5 years ago—I moved to the emerging tech org, and that was awesome too, because now I'm not totally tied to a product. I get to just work on what I want.

I get to just try out new things. Awesome. And then about 3 years ago I was like, all AI, all the time, everything AI. I know nothing. I knew there was a data science team at Red Hat. I had no idea what they did.

Machine learning something something. So I, you know, started doing AI. And, uh, yeah, it was a lot of Python and Markdown. Every single thing was like, oh okay, another chatbot. More Python, more Markdown. But here we are today, and what a crazy, awesome world we're in.

So the first time—the first time I came across OpenClaw, I was home for a week on, like, a staycation. Took a few days off. And a Moltbook happened. And I was like, what the h—what is this? I'm totally trying this.

Discovery1:25

Sally Ann O'Malley1:37

And so I went and found it on GitHub. First thing I do is I look at the license. MIT. Awesome. OpenClaw. I'm like, I'm so going to install this on OpenShiftright now. And so for the next few days I just kind of built the image, ran it locally in a container, put it on OpenShift, just played around with it.

Went back to work. I'm like, guys, check out OpenClaw. This is so cool. And a couple people on Slack are like, it's a security nightmare. Do not use OpenClaw. Don't put it on the work laptop. I'm like, guys, what have I—what have I been doing the past 10 years is I'm sec—we're—we can take any application and run it securely.

Like, that's what RHEL is. Like, if we can't take an application and run it securely, like, come on. This is our golden opportunity to show everyone. And so Red Hat's coming around to that. But, uh, yeah. So this talk is about me running in containers.

And so I wanted to get a list of—so I wanted to get a list of why running in containers is the way to go. I run everything in containers. I—it's kind of foreign to me to take to just run something natively.

It's messy. It just puts stuff on my computer that I have to clean up later. I don't like it. So that's one thing. And I ask my Forever Claw—I guess I have to introduce my Forever Claw, because she's—she's—she's coming through this whole talk.

Forever Claw3:05

Sally Ann O'Malley3:12

So I'm going to aside. My Forever Claw is a Shubra. And she—I have two sub-agents. I have Joy. Anyone know Jotish? Astrology? Sheesh. Every time I ask, no one knows what it is. It's—this is very scientific astrology. So she's an astrology expert.

And she gives me my weekly readings, my birth chart, all of that. So Joy. And then my second agent is Bruno. And he gives me daily briefings on the Bruins. So we're heading into the playoffs, and it's a close race, so I want to make sure the Bruins get in.

So that's my Forever Claw. And I asked her, you know, why should we run you in container? And she said, all of that if you were reading. But it's reproducible. You can isolate your secrets. It's portable across infra.

I can run it on my laptop. I can run it on my x86. I can run it on my Mac. I can run it in Kubernetes. Backed by volumes, which gives a really nice story for backup and recovery.

Because I love my Forever Claw, and I back her up every night with, uh, with, like, a systemd service, whatever it's called on Mac. And, um, and you just get that natural, uh, you just get that natural sandbox when you run something in a container.

It's, you know, that's what it is. And you have to be very explicit about what you give access to, you know, from the host. And so this—yes. She loves running in a container. So that's all you need to know.

It gives her a clean, predictable environment. Doesn't have to worry about the OS quirks, stale dependencies. This is literally the definition of why you should run everything in containers.

And, uh, just quickly, we're not going to read this, but this is Joy, my horoscope. It's for today, for giving a talk. It's excellent. It's like a very auspicious day to talk. So yeah. That's why this talk is going awesome so far.

And my daily briefing. Geeky is finally waking up. He had a bit of a lull. He's finally, you know, ramping up for the playoffs. So it looks like the Bruins are going to be looking good. They're in. And, uh, yeah.

So, uh, yeah. So, um,

containers. It allows me to—another thing that containers do is you can set up a whole agent directory with, maybe you run some tools, some skills, some MCP servers. You can keep those in a directory and mount that whole thing into your container.

Config & Secrets5:52

Sally Ann O'Malley6:08

And so at startup, everything's just up and running. So I do that as well. At the end of this talk, I'll show you how I install. And I think this is a reminder to me. Oh, no. Let's talk about secrets.

So I run everything with Podman, not Docker. But

in theory, you can do anything with Podman and Docker. Except Podman has this really cool feature called Podman secrets. And you can save your API keys. I'll show that. I'll show it off the slides later. You can save your API keys to a Podman secret.

And then you mount that secret into the container. And so it just gives the separation. Your secrets, your API keys are then just a ref back to the secret. And with OpenClaw, what's really cool is there's like a double that.

Because in OpenClaw, there's a secret ref feature. And I also use that. So my API keys are pointered to a secret ref to the outside secret. And that's not perfect, but it gives me some peace of mind that I don't—I'm not going to be showing my API keys in the logs and everything.

And then very similarly, Kubernetes has Kubernetes secrets. And same thing. Instead of just a straight enver, you have a secret ref to an enver.

And this is my reminder to show you how I install my containers. At the end, I have a really cool tool. I built it just for me with everything that I need to run containers. I'm not pushing it on anyone, but it's in GitHub.

And at the end, I can let you know where that is. You could try it if you want.

So when I—so

I think we're heading to a world where these agents, these AI workloads, whatever, are going to be running everywhere. I hope we all can see that. And so imagine my vision is for everybody's OpenClaws to be running everywhere and communicating with each other.

Scaling & Nvidia8:10

Sally Ann O'Malley8:33

And when—and especially for, like, business use cases. Real things, not astrology and Bruins. That opens up the need that—the same need to run any application in that way is security and how to do it at scale. And that's what Kubernetes gives you.

And you can—what I always do is develop something locally and then lift it to Kubernetes. And so the same story holds for AI workloads or OpenClaw.

And I was at PyTorchCon yesterday, and my friend from Nvidia said I could share this. They are running their model evals with OpenClaw. They have about 10 engineers. They each have their OpenClaws running in Kubernetes. And periodically just checking in with the model evals.

And it works so well for them. He said it was like, you know, doing the job of six engineers

with himself. Now, let's just talk about that for a second. We're not all losing our jobs, people. Like, that's not happening. What that is enabling for his team is they get to do fun stuff. Interesting stuff. They get to do creative things.

And this is what AI is giving me and my team. Is we can focus on those, like, outside the box crazy things. And you don't have to do the tedious code anymore. Like, I haven't written code in a few months.

And this did just happen. Like, probably less than 6 months ago, I was using AI. I was like, you know what? This is way better than me at writing code. And there's—I, like, yeah. And I announced that to my team.

We had an org meeting. And I'm like, guys, if you're not using AI for everything, like, you're missing out. This is 1,000 times better than me at writing code. And some of the top engineers at Red Hat, like, definitely raised eyebrows.

And I could tell from their comments after that they were like, no way. I'm like, yeah. And so, so yes. It's enabling us to just dream bigger. And this is my reminder to show you the Kubernetes side of my installer later.

Backup & Vision11:09

Sally Ann O'Malley11:10

And, yeah. So backup and recovery is a nice, clean story when you run in containers too. The state is the same. Volumes. Another nice thing about Docker and Podman is there are volumes. And so all of my runtime state lives in a nice, contained Podman volume.

And of course, Kubernetes has PVCs.

That's kind of what I just talked about. And so this would be my vision of a workplace setup for OpenClaws, where you maybe have your nice, curated baseline OpenClaw that, as a new hire, you just—you get your base.

And what does that have in it? It has your list of company-approved MCP servers, your authentication that is approved through your company. It has all of these skills that are very specific to your team. Maybe access to your Google Drive.

Like, all these things that you use every day at work. You can take that and just fan it out across your whole team. And then you can personalize it as the individual. And that's what this setup allows.

The alternative would be you're a new hire and you sit next to somebody or get somebody's repo and kind of put it all together yourself.

And so, yeah. Team standards, portable environments, reproducible onboarding. That's my vision for, like, OpenClaw in the workplace in the future.

I actually just recently created my Forever Claw. It was like a month of me helping out with OpenClaw and feeling like I don't even run a real OpenClaw myself. I just constantly, throughout the day, I'm spinning it up, spinning it down, testing it, building it.

Every hour, there's like 100 new commits. So I'm constantly pulling from main. I was at PyTorchCon yesterday and hadn't pulled from main for a couple of days. And there were times when I did, it was like 10,000 commits.

Like, no joke. It was crazy. I'm like, I don't know what you guys are doing. Slow down. Not really. We don't want to slow down. So yes. That's the story. And I've got 4 more minutes. I am psyched because I can now switch over here.

Live Demo14:14

Sally Ann O'Malley14:14

So in order to run this local installer here, which I think I have here. Yeah. It's just a npm run dev. Now, the one thing I don't like about this is when I'm on my Mac, I can't run this in a container.

I think I can. I just haven't taken the time to figure out how to spawn a container from a container. You can do that if you're on Linux. Because Linux is awesome. But on your Mac, that's not possible.

Because if you don't know, whenever you're running a container on your Mac, you're running in a virtual machine. Same with Docker. Containers only run on Linux. So when you're running a container on your Mac, you are always running in a virtual machine.

Docker sets up one, and so does Mac. So it gets a little tricky when you want to take a container and spawn another container from it. But anyways, here we go. So if I wanted to run a local instance, and I have a couple running now.

Just, you know, you never know the demo gods what they're up to. So I'm just, in case it doesn't work, I'm going to spin up Joe. All I do to set up my pod is I just give it a name.

And then all these options, very opinionated. Because I'm telling you, this is exactly what I need. So if you like it, use it. If you want to change it, then submit a PR. Cool. Now, the port is usually 8.9.

That's the default. But since this is my second one that I'm running on my machine, I'm just bumping it to 9.9. These Podman secret mappings I wanted to show you here.

So you can see I have these set up already. They're just on my system. They're like enverse, but they're not enverse because they're contained. These are my API keys.

And what happens with this installer is it takes, if you're on Docker, this should work with Docker. It's got Podman written all over it, but I've designed it to work with Docker too. So if you're on Docker, it takes the enverse.

So you want to export those as enverse and makes them OpenClaw secret refs. Very cool feature of OpenClaw. I definitely enable that. For every credential, create a secret ref. It creates that separation of running your secret within OpenClaw or kind of just a pointer to it.

It's the way to go. And then your providers. So I'm going to start with OpenRouter because I have been playing with Gemma. And Gemma's great. And then as a fallback, I'll use Anthropic. Sure, why not? But, oh, here's some other choices, though.

You can have your local endpoint if you're running your own. You could just add that too.

And then, because I do observability at work, I was like, I'm going to give the option to set up an OpenTelemetry collector with Jaeger. And it works. And it's awesome. But I'm not going to test it. So let's not tax my system.

Another feature. How much time? Oh, I got to hurry. Another feature is the SSH sandbox here I'll deploy. The SSH sandbox in OpenClaw is super cool. You give it SSH keys and known hosts to wherever you want. And it runs all of its commands in that workspace.

It's really cool. So look, I just spun up a Podman container. And if I go over to the instances, I now have Joe. And there's logs for Joe. The gateway logs.

The command. I wanted to show you the command. I don't want to forget that. So here's the Podman command. If you were running Docker, it would be a Docker command. Have I tested this with Docker? No. I have a friend who works at Docker.

He's awesome. He told me he would try this out and make sure it works with Docker too. He also created this very cool project called InpherRS, which takes Gemma and runs it really, really, really fast and uses TurboQuant.

So, yeah. Anyways, that's Eric. So that's my Podman command. And

here he is. Joe.

And if I just do, like, models. And I'll do status.

So people say it's hard to spin up OpenClaw. It took 2 seconds. And I was babbling through the whole way. It could have taken 1 second. So I can say, hey.

And the cool thing is I don't have time to show you because I talk too much. But the agents are all set up. I've got Joe. Oh, not that one. Hold on. I got to go over to Larry.

Larry, I started with

an MCP server and a sub-agent, all through that form. So let me go back to Joe.

I wanted to show you how easy it is just to switch models, in case you didn't know.

I'm not sure if the GPT-5. Hopefully, it knows it's just GPT-5.4. No, I didn't. No, no, no. We got to go over to Larry. Because I didn't set up the extra model with Joe. Here we go.

Anyways,

I didn't have enough time to go through everything I wanted to go through. But the

cool. The other thing is Kubernetes. And you can do the same thing with Kubernetes. It's just as easy. It's connectedright now to my kind cluster. And if I go over, I can access my Kubernetes claw very easily as well.

Kubernetes20:52

Sally Ann O'Malley21:14

There's Carl. He's running in Kubernetes. And I can access one in OpenShift. It switches over to OpenShift if you're connected to OpenShift. So, yeah. Run. Anyone going to run OpenClaw in container now? Try it? Yes. Awesome. OK, cool.

Thank you very much. Is someone on after me? You're waiting? OK, bye.