
> دليل تدقيق أمان OpenClaw والنشر المُحصّن — الثغرات المعروفة (CVE-2026-25253، المهارات الخبيثة، تسريب بيانات الاعتماد)، والتخفيفات المعمارية، وخطة نشر خطوة بخطوة على خادم VPS
وثائق عامة منقّحة حول النشر الآمن لـ OpenClaw على VPS: بنية الوصول، الثغرات المعروفة، والحوادث العملية مع الحلول.
وثائق عامة ومنقّحة من عمليات OpenClaw الحقيقية: كيفية نشر المنصة على VPS دون كشف البوابة، وما هي CVEs/المشكلات المهمة عمليًا، وما الذي فشل في الإنتاج (مع الإصلاحات).
الإصدار الحالي: v1.2 · سجل التغييرات · إصدارات GitHub
| RU | EN |
|---|
| الجمهور | مشغّلو OpenClaw المستضاف ذاتيًا | Operators self-hosting OpenClaw |
| الهدف | تجنّب أخطاء الأمان والتوقفات الشائعة من التشغيل الحقيقي | Avoid common security mistakes and downtime modes found in real use |
| المحتوى | نظرة عامة، خطة نشر خطوة بخطوة (RU+EN)، تحليلات الحوادث | Overview, step-by-step deployment plan (RU+EN), incident post-mortems |
| غير مشمول | النطاقات، عناوين IP، رموز البوتات، الأسعار، المسارات الشخصية | Private hostnames, IPs, bot tokens, prices, personal paths |
هذه وثائق، وليست fork من OpenClaw ولا مثبّتًا. الإصدار المشار إليه في الحوادث عادةً هو OpenClaw v2026.3.x.
This is documentation, not an OpenClaw fork or installer. Platform version referenced in incidents is typically OpenClaw v2026.3.x.
النظرة العامة وخطة النشر توضحان كيفية الإعداد. الحوادث تُظهر ما تعطّل في التشغيل الحقيقي وأي معايرة/إعدادات أصلحت ذلك — حتى لا يكرر القارئ نفس الأخطاء.
The overview and deployment plan say how to configure. Incidents show what broke in real operations and which calibrations/config fixes resolved it — so readers do not repeat the same failures.
هي موجودة في المستودع كتحليلات عملية post-mortem بجانب التوصيات، وليس كـ«سجل أخبار» منفصل.
They belong in the repo as practical post-mortems next to the recommendations, not as a separate news feed.
RU
incident_*.md — الأعطال المحددة والمعايرات (انظر لماذا أعلاه)EN
incident_*.md files — failures and fixes (see why above)127.0.0.1؛ لا تنشر منافذ OpenClaw للخارج. / Gateway and Web UI on 127.0.0.1 only; do not publish OpenClaw ports.HTTPS_PROXYchannels.telegram.proxymode=all مع حدود الذاكرة (sandbox وحده لا يحمي من OOM في Chromium). / Docker sandbox mode=all plus memory limits (sandbox alone does not stop Chromium OOM).| الملف | المحتوى |
|---|---|
| CHANGELOG.md | سجل الإصدارات / Version history |
| openclaw_обзор_public.md | RU — نظرة عامة على المنصة، الأمان، التثبيت، المراقبة |
| openclaw_overview_public_en.md | EN — same overview |
| развёртывание_решение_public.md | RU — خطة النشر (المراحل 0–12)، النتائج، المهام المؤجلة |
| deployment_plan_public_en.md | EN — same deployment plan |
| incident_telegram_selfheal_2026-03-11.md | EN — post-mortem: selfheal → تجمّد Telegram |
| incident_telegram_media_proxy_2026-03-14.md | EN — post-mortem: MediaFetchError; channels.telegram.proxy |
| incident_sandbox_oom_2026-04-10.md | EN — post-mortem: OOM Chromium في sandbox; حدود الذاكرة |
RU
config set، تخفيفات عملية)EN
config set, practical mitigations)تاريخ الإنشاء: 22 فبراير 2026، 00:24 تاريخ التحديث: 4 سبتمبر 2026، 01:30