OpenClaw on AWS Lightsail: Cost Breakdown and Configuration Lessons

OpenClaw on AWS Lightsail Configuration and Costs
A developer attempted to build a personal assistant bot called "Belvedere" using OpenClaw on AWS Lightsail with Claude Sonnet 4.6 via Bedrock. The setup involved two Lightsail instances (medium_3_0, 4GB, $40/mo each) running the openclaw_ls_1_0 blueprint in us-east-1, aiming to manage family calendars, school logistics, travel booking, and morning briefings via Telegram.
What Worked
The system successfully pulled JetBlue fares via headless Chromium, cross-referenced work calendars against family commitments, and flagged scheduling conflicts. It connected to Google Calendar via gogcli, read Gmail via himalaya (read-only), and pulled credentials from 1Password.
What Didn't Work
- Sandbox Issues: The Lightsail blueprint ships with sandbox mode set to "all," which broke gog, himalaya, op CLI, and cron jobs. The undocumented fix was changing sandbox mode to "non-main" (valid values are "all", "non-main", and "off").
- Cron Problems: Morning briefing cron jobs ran inside sandbox containers without access to host binaries or the gateway websocket, causing failures and inconsistent execution times (sometimes firing on UTC instead of ET).
- Permission Issues: Basic commands like
npm install -g openclaw@latestfailed without sudo due to root-owned global npm directories. - Setup Hurdles: Bedrock First Time User form required submission both via webform and CLI, with 3-4 hour delays between attempts.
- Token Management: The gateway auth token embedded in systemd service files rotated frequently, requiring frequent
--accept-latestlogin checks.
Cost Breakdown
The AWS bill for one week totaled $98.31:
- Bedrock (Claude Sonnet 4.6): $69.61
- Lightsail: $8.17
- Other (WAF, Route53, EC2): $20.53
$64 of the Bedrock bill came from a single heavy setup day with 567 invocations, each carrying 10-15K tokens of context. The system prompt (AGENTS.md alone is 8KB, plus SOUL.md, USER.md, and memory files) gets sent on every API call. With 30-minute heartbeat polling, that's ~48 calls/day just for heartbeats.
Recommendations
- Skip Lightsail entirely in favor of a $5 VPS on Hetzner or DigitalOcean with the Anthropic API directly (~$20-35/month at this usage level).
- Change sandbox to "non-main" or "off" immediately instead of the default "all."
- Trim AGENTS.md from the default 8KB boilerplate that ships with every API call.
- Reduce heartbeat frequency from 30 minutes to 1-2 hours for personal bots.
- Set timezone explicitly everywhere since OpenClaw and cron don't always agree on "local time."
📖 Read the full source: r/openclaw
👀 See Also

How a Solo SaaS Founder Uses Claude's Project Knowledge to Save 20-30 Minutes Daily
A solo founder running a CRM for Indian SMBs ($11.2K MRR) shares how Claude's Project Knowledge feature replaced daily context-setting with persistent, curated knowledge across product, customer, and growth domains.

Non-developer builds crypto risk API with Claude in one afternoon
A former futures trader with no development background used Claude to build and deploy RiskSnap, a FastAPI endpoint that scores crypto portfolios across 7 risk dimensions. The project includes a live API, custom domain, and full documentation.
Local vs VPS OpenClaw deployment: practical differences for AI coding agents
Running OpenClaw locally provides real browser access with existing login sessions and local file access, while VPS deployment limits functionality to basic tasks and faces website restrictions.

Claude Code User Details Production App Challenges: Security, Compliance, and Edge Cases
A developer building a personal finance app with Claude Code for six months shares specific production challenges: security audits revealed self-escalation vulnerabilities and data leaks, Plaid integration required LLC/EIN setup and had technical bugs, and App Store rejections for non-technical issues.