OpenClaw on AWS Lightsail: Cost Breakdown and Configuration Lessons

OpenClaw on AWS Lightsail Configuration and Costs
A developer attempted to build a personal assistant bot called "Belvedere" using OpenClaw on AWS Lightsail with Claude Sonnet 4.6 via Bedrock. The setup involved two Lightsail instances (medium_3_0, 4GB, $40/mo each) running the openclaw_ls_1_0 blueprint in us-east-1, aiming to manage family calendars, school logistics, travel booking, and morning briefings via Telegram.
What Worked
The system successfully pulled JetBlue fares via headless Chromium, cross-referenced work calendars against family commitments, and flagged scheduling conflicts. It connected to Google Calendar via gogcli, read Gmail via himalaya (read-only), and pulled credentials from 1Password.
What Didn't Work
- Sandbox Issues: The Lightsail blueprint ships with sandbox mode set to "all," which broke gog, himalaya, op CLI, and cron jobs. The undocumented fix was changing sandbox mode to "non-main" (valid values are "all", "non-main", and "off").
- Cron Problems: Morning briefing cron jobs ran inside sandbox containers without access to host binaries or the gateway websocket, causing failures and inconsistent execution times (sometimes firing on UTC instead of ET).
- Permission Issues: Basic commands like
npm install -g openclaw@latestfailed without sudo due to root-owned global npm directories. - Setup Hurdles: Bedrock First Time User form required submission both via webform and CLI, with 3-4 hour delays between attempts.
- Token Management: The gateway auth token embedded in systemd service files rotated frequently, requiring frequent
--accept-latestlogin checks.
Cost Breakdown
The AWS bill for one week totaled $98.31:
- Bedrock (Claude Sonnet 4.6): $69.61
- Lightsail: $8.17
- Other (WAF, Route53, EC2): $20.53
$64 of the Bedrock bill came from a single heavy setup day with 567 invocations, each carrying 10-15K tokens of context. The system prompt (AGENTS.md alone is 8KB, plus SOUL.md, USER.md, and memory files) gets sent on every API call. With 30-minute heartbeat polling, that's ~48 calls/day just for heartbeats.
Recommendations
- Skip Lightsail entirely in favor of a $5 VPS on Hetzner or DigitalOcean with the Anthropic API directly (~$20-35/month at this usage level).
- Change sandbox to "non-main" or "off" immediately instead of the default "all."
- Trim AGENTS.md from the default 8KB boilerplate that ships with every API call.
- Reduce heartbeat frequency from 30 minutes to 1-2 hours for personal bots.
- Set timezone explicitly everywhere since OpenClaw and cron don't always agree on "local time."
📖 Read the full source: r/openclaw
👀 See Also

Claude Code's /insight command analyzes developer workflow patterns from real usage data
A developer building a personal finance iOS app used Claude Code's new /insight command to analyze 22 days of usage: 529 messages, 47,604 lines of code, 632 files touched, and 146 commits. The report identified effective patterns like an 'audit-then-batch-fix pipeline' and flagged time-wasters like debugging loops.

Claude Code Audits 80-Component React Library Docs: Real Bugs Found, New Bug Introduced
A staff engineer used Claude Code to audit docs for an 80-component React library. It caught real bugs but also introduced new ones requiring a review pass.

Daily 3.5-Hour Voice + Claude Workflow: Dictate Specs While Walking, Build with Claude Code
A developer walks 3 dogs 12+ times daily (3.5 hours) and uses voice + Claude to brainstorm, research, and produce spec.md files. Then Claude Code builds from those specs.

OpenClaw integrates with Kroger API for automated grocery shopping via AI agents
A developer used OpenClaw with the Kroger API to automatically add recipe ingredients to a shopping cart, leveraging Qwen3.5 for recipe generation and Gemini 3.1 Pro for setup. The integration required 6 hours of work and consumed 359K tokens for a single cart generation.