Notícias
Notícias
5 min de leitura
5 de outubro de 2026

Seu agent na nuvem custa caro. Self-hosted = 80% mais barato.

Self-hosted HTTP tunnels via SSH enable on-premises agent deployment. Cloud costs = suddenly optional. Your agents = no longer vendor lock-in.

Equipe OpenClaw

Equipe OpenClaw · Time de Engenharia & Produto

A Equipe OpenClaw é formada por engenheiros, designers e especialistas em IA dedicados a construir a melhor plataforma de agentes conversacionais para negócios brasileiros. Combinamos expertise…


Seu agent na nuvem custa caro. Self-hosted = 80% mais barato.

Ontem publicação importante: Self-hosted HTTP tunnels com SSH + Nginx.

"HTTP tunneling via SSH = agents can communicate securely through firewalls (no port exposure). Translation: Deploy agents on your own infrastructure (on-premises, behind NAT, air-gapped networks). You don't need AWS/Google. You don't pay cloud bills. Vendor lock-in = broken."

What this means: Your agents can run on your servers, not cloud.

Why it matters: Cloud agent = R$ 10K-50K/month. On-premises agent = R$ 500-2K/month. 80%+ cost reduction.

Problem it reveals: Founders think "agent = must be cloud." Wrong. Self-hosted = now viable (and cheaper).

Você é founder.

Current reality (2026 - Cloud-only agent deployment, high costs):

YOUR CURRENT AGENT SETUP (Cloud-dependent, expensive):

├─ What self-hosted HTTP tunneling reveals: │ ├─ Technology: SSH + Nginx can tunnel HTTP through secure channel │ ├─ Implication: Agents don't need cloud infrastructure (AWS/GCP/Azure) │ ├─ Deployment: Agents can run on-premises (your own servers) │ ├─ Network: Works behind NAT/firewalls (no port exposure) │ ├─ Cost: Dramatically lower (no cloud bills) │ ├─ Vendor lock-in: Eliminated (not dependent on cloud provider) │ ├─ Data sovereignty: Complete control (stays on your infrastructure) │ └─ Compliance: Easier for regulated industries (HIPAA, PCI, LGPD) │ ├─ Your current cloud agent cost structure: │ ├─ Cloud compute (agent servers): │ │ ├─ Small agent (micro instance): R$ 200-500/month │ │ ├─ Medium agent (standard instance): R$ 1K-3K/month │ │ ├─ Large agent (high CPU): R$ 3K-10K/month │ │ ├─ Very large agent (multiple instances): R$ 10K-50K+/month │ │ └─ Your scenario: Probably R$ 2K-10K/month (dependent on scale) │ │ │ ├─ Cloud database (agent data): │ │ ├─ Managed database: R$ 500-2K/month (storage + backups) │ │ ├─ Database scaling: R$ 1K-5K/month (if scaled) │ │ └─ Your scenario: Add R$ 500-2K/month │ │ │ ├─ Cloud bandwidth (agent requests): │ │ ├─ Data transfer out: R$ 0.10 per GB │ │ ├─ Normal agent: 100GB/month = R$ 10/month (negligible) │ │ ├─ High-volume agent: 1TB/month = R$ 100/month (small) │ │ └─ Your scenario: R$ 10-100/month (usually small) │ │ │ ├─ Cloud monitoring/logging: │ │ ├─ CloudWatch / Stackdriver: R$ 100-500/month │ │ ├─ APM / error tracking: R$ 200-1K/month │ │ ├─ Log storage: R$ 100-500/month │ │ └─ Your scenario: R$ 400-2K/month (if doing it right) │ │ │ ├─ Cloud load balancers / API gateways: │ │ ├─ Application load balancer: R$ 200-500/month │ │ ├─ API gateway: R$ 100-500/month │ │ └─ Your scenario: R$ 300-1K/month │ │ │ ├─ Cloud security (certificates, DDoS, WAF): │ │ ├─ SSL certificate: R$ 100-500/month (managed) │ │ ├─ DDoS protection: R$ 200-2K/month (optional but recommended) │ │ ├─ Web Application Firewall: R$ 100-1K/month │ │ └─ Your scenario: R$ 400-3.5K/month │ │ │ ├─ Cloud storage (if agent stores files): │ │ ├─ S3 / Cloud Storage: R$ 1-10/month (usually minimal) │ │ └─ Your scenario: R$ 0-50/month │ │ │ ├─ Miscellaneous / margin: │ │ ├─ Unexpected charges: ~10% of total │ │ └─ Your scenario: R$ 200-2K/month │ │ │ └─ TOTAL MONTHLY COST: │ ├─ Small agent: R$ 2.5K-6K/month │ ├─ Medium agent: R$ 5K-15K/month │ ├─ Large agent: R$ 15K-50K+/month │ ├─ Annual cost: R$ 30K-600K/year (significant) │ ├─ Assumption: You're paying because you think you MUST (cloud-only) │ └─ Reality: You CAN deploy on-premises for 80%+ savings │ ├─ Self-hosted agent cost structure (on-premises via SSH tunnel): │ ├─ Hardware investment: │ │ ├─ Used server (Dell PowerEdge, HP ProLiant): R$ 2K-5K (one-time) │ │ ├─ Co-location (if not in your office): R$ 300-1K/month │ │ ├─ OR: Rent dedicated server (cheaper than cloud): R$ 500-2K/month │ │ └─ Comparison: Cloud = R$ 5K/month recurring, Self-hosted = R$ 2K one-time + R$ 500/month │ │ │ ├─ Network / connectivity: │ │ ├─ SSH tunnel (secure, no port exposure): Free (built-in) │ │ ├─ Nginx reverse proxy: Free (open-source) │ │ ├─ SSL certificate (Let's Encrypt): Free (automated) │ │ └─ Total networking: R$ 0-100/month (minimal) │ │ │ ├─ Database (self-hosted): │ │ ├─ PostgreSQL / MySQL (open-source): Free (software) │ │ ├─ Disk storage: R$ 100-500/month (if rented co-lo) │ │ ├─ Backups (automated): Free (script on same server) │ │ └─ Total database: R$ 100-500/month (if co-located) │ │ │ ├─ Monitoring / logging (self-hosted): │ │ ├─ Prometheus (open-source monitoring): Free │ │ ├─ Grafana (open-source dashboards): Free │ │ ├─ ELK stack (open-source logging): Free │ │ ├─ Disk for logs (100GB/month): R$ 100-300/month │ │ └─ Total monitoring: R$ 100-300/month (minimal) │ │ │ ├─ Maintenance / operations: │ │ ├─ Your engineer time: 4-8 hours/month (R$ 1K-2K value) │ │ ├─ Tools / automation: R$ 0-500/month (optional) │ │ └─ Total operations: R$ 500-2.5K/month (depends on engineer cost) │ │ │ └─ TOTAL MONTHLY COST (on-premises): │ ├─ Server rental: R$ 500-2K/month │ ├─ Monitoring: R$ 100-300/month │ ├─ Maintenance: R$ 500-2K/month (your time) │ ├─ Miscellaneous: R$ 100-300/month │ ├─ Total: R$ 1.2K-4.6K/month │ ├─ Comparison to cloud: 60-80% CHEAPER │ ├─ Annual savings: R$ 30K-150K/year │ └─ Investment payback: 1-3 months (if you have an engineer) │ ├─ FINANCIAL COMPARISON (Why self-hosted wins): │ ├─ Scenario 1: Small SaaS (1 agent, 100 customers) │ │ ├─ Cloud cost: R$ 3K/month = R$ 36K/year │ │ ├─ Self-hosted cost: R$ 1.5K/month = R$ 18K/year │ │ ├─ Savings: R$ 18K/year (50%) │ │ ├─ Payback: 1 month (if using existing engineer) │ │ └─ Conclusion: Self-hosted is obvious choice │ │ │ ├─ Scenario 2: Medium SaaS (5 agents, 1000 customers) │ │ ├─ Cloud cost: R$ 15K/month = R$ 180K/year │ │ ├─ Self-hosted cost: R$ 3K/month = R$ 36K/year │ │ ├─ Savings: R$ 144K/year (80%) │ │ ├─ Payback: 2-3 weeks (one-time hardware investment) │ │ └─ Conclusion: Self-hosted is financially compelling │ │ │ ├─ Scenario 3: Large SaaS (20+ agents, 10K+ customers) │ │ ├─ Cloud cost: R$ 50K+/month = R$ 600K+/year │ │ ├─ Self-hosted cost: R$ 10K/month = R$ 120K/year │ │ ├─ Savings: R$ 480K+/year (80%) │ │ ├─ Payback: 1-2 weeks │ │ ├─ Dedicated ops team: R$ 30K-50K/month (justified) │ │ ├─ Total self-hosted: R$ 40-60K/month │ │ ├─ Still cheaper than cloud by: R$ 200K-500K/year │ │ └─ Conclusion: Self-hosted is strategically mandatory │ │ │ ├─ Break-even analysis: │ │ ├─ Initial self-hosted investment: R$ 5K-20K (one-time hardware) │ │ ├─ Monthly savings: R$ 2K-40K (depending on scale) │ │ ├─ Payback period: 2-10 days (for most SaaS) │ │ ├─ Multi-year savings: R$ 100K-500K+ (very significant) │ │ └─ Financial conclusion: Self-hosted ROI is obvious │ │ │ └─ Why founders still use cloud (misconceptions): │ ├─ Myth 1: "Self-hosting is complicated" │ │ ├─ Reality: SSH tunnel + Nginx = simple (documented) │ │ ├─ Learning curve: 1-2 days for competent engineer │ │ └─ Complexity vs cost savings: Easy trade-off │ │ │ ├─ Myth 2: "Self-hosting is less secure" │ │ ├─ Reality: SSH tunnel = encrypted (actually more secure) │ │ ├─ Your control: Complete (vs cloud provider's policies) │ │ ├─ Data sovereignty: Complete (vs cloud provider's access) │ │ └─ Security vs cost: Better security + lower cost │ │ │ ├─ Myth 3: "Self-hosting is less scalable" │ │ ├─ Reality: Multi-server setup = easily scalable │ │ ├─ Load balancing: Simple (Nginx does this) │ │ ├─ Database replication: Available (PostgreSQL/MySQL) │ │ └─ Scalability vs cost: 10x better cost + same scalability │ │ │ ├─ Myth 4: "Self-hosting requires operations team" │ │ ├─ Reality: Most operations = automated (cron, scripts) │ │ ├─ Team size: 0.5-1 engineer (vs cloud infrastructure engineers) │ │ ├─ Cost of operations: R$ 500-2K/month (vs paying cloud bills) │ │ └─ Operations vs cost: Smaller team + lower cost │ │ │ ├─ Myth 5: "Self-hosting means no uptime SLA" │ │ ├─ Reality: You control your infrastructure │ │ ├─ Reliability: Can be 99.9%+ (with redundancy) │ │ ├─ Backup/recovery: Simpler (no cloud vendor dependency) │ │ └─ Reliability vs cost: Better control + lower cost │ │ │ ├─ Myth 6: "I need cloud for compliance" │ │ ├─ Reality: Compliance = audit trail + controls (you implement) │ │ ├─ HIPAA/PCI/LGPD: Possible on self-hosted (with setup) │ │ ├─ Data residency: Guaranteed (on your servers) │ │ └─ Compliance vs cost: Better compliance + lower cost │ │ │ └─ Truth: Most founders avoid self-hosting = lack knowledge │ ├─ Solution: SSH tunneling proves it's simple │ ├─ Implementation: 1-2 weeks to deploy │ ├─ Savings realization: Immediate (within 1-3 months) │ └─ Competitive advantage: Early movers lock in 80% cost reduction │ ├─ HOW TO DEPLOY SELF-HOSTED AGENTS (SSH tunneling architecture): │ ├─ Architecture overview (high-level): │ │ ├─ Your agents: Run on your infrastructure (on-premises/dedicated server) │ │ ├─ SSH tunnel: Secure encrypted channel from agent to outside │ │ ├─ Nginx reverse proxy: Sits between tunnel + external clients │ │ ├─ Clients: Connect to Nginx (which routes to your agents via tunnel) │ │ ├─ Result: Your agents are accessible externally (no port exposure) │ │ ├─ Security: Encrypted tunnel (SSH) + no open ports (NAT-friendly) │ │ └─ Network diagram: │ │
│ │ [Your agents on your server] │ │ ↓ │ │ [SSH tunnel] │ │ ↓ │ │ [Nginx reverse proxy] │ │ ↓ │ │ [External clients] │ │
│ │ │ ├─ Step 1: Get infrastructure │ │ ├─ Option A: Dedicated server (OVH, Linode, DigitalOcean) │ │ │ ├─ Cost: R$ 500-1.5K/month (VPS is cheaper than cloud app hosting) │ │ │ ├─ Setup: 15 minutes (pre-configured Linux) │ │ │ ├─ Advantage: Control + simplicity │ │ │ └─ Recommendation: Best for most SaaS │ │ │ │ │ ├─ Option B: Your own hardware │ │ │ ├─ Cost: R$ 2K-5K (one-time) + R$ 100-300/month (co-location) │ │ │ ├─ Setup: 1-2 days (if not already in data center) │ │ │ ├─ Advantage: Own hardware = no landlord dependency │ │ │ └─ Recommendation: Good if you have hardware already │ │ │ │ │ └─ Option C: Cloud servers (still cheaper than app hosting) │ │ ├─ Cost: R$ 300-1K/month (bare metal instance) │ │ ├─ Setup: 5 minutes (cloud console) │ │ ├─ Advantage: Ease of cloud provisioning │ │ └─ Recommendation: Good if already using cloud (better to use dedicated server) │ │ │ ├─ Step 2: Set up SSH tunnel (reverse port forwarding) │ │ ├─ Concept: Your agent server creates outbound SSH connection │ │ │ ├─ Local side: Agent server (port 8080) │ │ │ ├─ Remote side: Tunnel endpoint (Nginx server) │ │ │ ├─ Tunnel direction: Reverse (server initiates, stays open) │ │ │ └─ Result: External clients connect to Nginx, traffic routes through tunnel to agents │ │ │ │ │ ├─ Command (on agent server): │ │ │ ├─ ssh -R 8080:localhost:5000 tunnel@example.com │ │ │ ├─ Explanation: │ │ │ │ ├─ -R = reverse port forwarding │ │ │ │ ├─ 8080 = port on remote (Nginx) machine │ │ │ │ ├─ localhost:5000 = agent's local address (where agent listens) │ │ │ │ ├─ tunnel@example.com = SSH server (Nginx host) │ │ │ └─ Result: Remote port 8080 → SSH tunnel → Local agent (port 5000) │ │ │ │ │ ├─ Make persistent (autorestart on disconnect): │ │ │ ├─ Tool: autossh (manages SSH connection reliability) │ │ │ ├─ Command: autossh -M 0 -R 8080:localhost:5000 tunnel@example.com │ │ │ ├─ Systemd service: Ensure tunnel restarts on reboot │ │ │ └─ Result: Tunnel always available (automatic recovery) │ │ │ │ │ └─ Security considerations: │ │ ├─ SSH key: Use key-based auth (no passwords, more secure) │ │ ├─ Firewall: Restrict tunnel port to Nginx server only │ │ ├─ Keep-alive: Enable SSH keep-alive (prevent timeout) │ │ └─ Monitoring: Alert if tunnel disconnects (automatic failover) │ │ │ ├─ Step 3: Set up Nginx as reverse proxy │ │ ├─ Nginx role: Sits on tunnel endpoint, routes external traffic to agent │ │ │ ├─ External clients: Connect to Nginx (example.com:443 HTTPS) │ │ │ ├─ Nginx local: Forwards to tunnel (localhost:8080) │ │ │ ├─ Tunnel: Encrypts + routes to agent server │ │ │ ├─ Agent: Receives request, responds │ │ │ ├─ Return path: Agent → Tunnel → Nginx → Client │ │ │ └─ Result: Seamless communication (client unaware of tunnel) │ │ │ │ │ ├─ Nginx config (simplified): │ │ │ nginx │ │ │ server { │ │ │ listen 443 ssl; │ │ │ server_name agent.example.com; │ │ │ ssl_certificate /etc/letsencrypt/live/...; │ │ │ ssl_certificate_key /etc/letsencrypt/live/...; │ │ │
│ │ │ location / { │ │ │ proxy_pass http://localhost:8080; # Forward to SSH tunnel │ │ │ proxy_set_header Host $host; │ │ │ proxy_set_header X-Real-IP $remote_addr; │ │ │ } │ │ │ } │ │ │
│ │ │ │ │ ├─ SSL/TLS certificate: Use Let's Encrypt (free, automated) │ │ │ ├─ Tool: Certbot (automatic certificate management) │ │ │ ├─ Command: certbot --nginx -d agent.example.com │ │ │ ├─ Renewal: Automatic (Certbot handles it) │ │ │ └─ Cost: Free (no vendor lock-in) │ │ │ │ │ ├─ Load balancing (if multiple agents): │ │ │ ├─ Nginx upstream: Round-robin across multiple agent tunnels │ │ │ ├─ Failover: Automatically skip failed agents │ │ │ ├─ Health checks: Monitor agent availability │ │ │ └─ Result: High availability (agent failure = automatic failover) │ │ │ │ │ └─ Performance tuning: │ │ ├─ Connection pooling: Reuse connections (reduce overhead) │ │ ├─ Buffering: Disable if not needed (reduce latency) │ │ ├─ Gzip compression: Enable (reduce bandwidth) │ │ └─ Caching: Nginx can cache responses (if applicable) │ │ │ ├─ Step 4: Deploy agent code (on your server) │ │ ├─ Agent runtime: Use Docker (simplifies deployment) │ │ │ ├─ Docker image: Build image with your agent code │ │ │ ├─ Container: Run agent in container (port 5000) │ │ │ ├─ Volumes: Mount config / data directories │ │ │ ├─ Network: Expose port 5000 (localhost only) │ │ │ └─ Orchestration: Docker Compose (simple) or Kubernetes (complex) │ │ │ │ │ ├─ Database (self-hosted on same server or separate): │ │ │ ├─ PostgreSQL / MySQL: Container or native install │ │ │ ├─ Connection: Agent connects to DB (localhost or IP) │ │ │ ├─ Backups: Automated (cron job → S3 / object storage) │ │ │ └─ Monitoring: Database health checks │ │ │ │ │ ├─ Logging / monitoring: │ │ │ ├─ Agent logs: Centralize to stdout (Docker captures) │ │ │ ├─ Log aggregation: ELK / Loki (optional, open-source) │ │ │ ├─ Metrics: Prometheus (open-source) │ │ │ ├─ Dashboards: Grafana (visualize metrics) │ │ │ └─ Alerts: Send to Slack / email on issues │ │ │ │ │ └─ CI/CD pipeline: │ │ ├─ Git push: Trigger deployment │ │ ├─ Build: Docker image build │ │ ├─ Test: Run test suite │ │ ├─ Deploy: Pull image, restart container │ │ └─ Result: New agent versions deploy automatically │ │ │ ├─ Step 5: Set up monitoring + alerting │ │ ├─ Tunnel health: │ │ │ ├─ Check if SSH tunnel is connected │ │ │ ├─ Alert if tunnel drops │ │ │ ├─ Auto-restart on failure (systemd or watchdog script) │ │ │ └─ Test: Kill tunnel, verify automatic recovery │ │ │ │ │ ├─ Agent health: │ │ │ ├─ HTTP health check (agent responds to /health) │ │ │ ├─ Nginx checks agent status regularly │ │ │ ├─ Alert if agent is down │ │ │ ├─ Auto-restart if needed │ │ │ └─ Test: Kill agent, verify automatic recovery │ │ │ │ │ ├─ Performance monitoring: │ │ │ ├─ Response time: Alert if slow (>1s) │ │ │ ├─ Error rate: Alert if >1% errors │ │ │ ├─ Resource usage: Alert if CPU/memory high │ │ │ ├─ Database performance: Monitor query latency │ │ │ └─ Dashboard: Real-time visibility (Grafana) │ │ │ │ │ └─ Alerting channels: │ │ ├─ Slack: Instant notifications for team │ │ ├─ Email: Backup alerts │ │ ├─ PagerDuty: On-call escalation (if high severity) │ │ └─ SMS: Critical alerts only (avoid noise) │ │ │ └─ Total setup time: 2-4 weeks │ ├─ Infrastructure setup: 1-2 days │ ├─ SSH tunnel + Nginx: 1-2 days │ ├─ Agent deployment: 2-3 days │ ├─ Monitoring setup: 2-3 days │ ├─ Testing + validation: 3-5 days │ ├─ Team training: 1-2 days │ └─ Total: 2-4 weeks (manageable project) │ ├─ COMPARING CLOUD VS SELF-HOSTED (Decision matrix): │ ├─ Cost: Self-hosted wins (80% cheaper) │ ├─ Time to deploy: Cloud wins (days vs weeks) │ ├─ Operational overhead: Cloud wins (managed for you) │ ├─ Data control: Self-hosted wins (complete ownership) │ ├─ Compliance: Self-hosted wins (data residency) │ ├─ Vendor lock-in: Self-hosted wins (no dependency) │ ├─ Scalability: Tie (both scalable, different trade-offs) │ ├─ Security: Self-hosted wins (you control) │ ├─ Flexibility: Self-hosted wins (customize anything) │ └─ Recommendation: │ ├─ Choose CLOUD if: Quick MVP (days matter) + can afford cost │ ├─ Choose SELF-HOSTED if: Cost matters + can wait 2-4 weeks │ ├─ Hybrid: Start cloud (quick), migrate self-hosted (reduce cost) │ └─ For most SaaS: Self-hosted ROI is obvious (do it) │ └─ THE BOTTOM LINE: ├─ SSH tunneling: Enables secure agent deployment (on-premises, no open ports) ├─ Self-hosting option: Now viable (previously thought impossible) ├─ Cost reduction: 60-80% cheaper than cloud (R$ 30K-500K+/year savings) ├─ Timeline: 2-4 weeks to deploy (manageable project) ├─ Operational overhead: 0.5-1 engineer (vs cloud infrastructure team) ├─ Data control: Complete (you own + control everything) ├─ Compliance: Easier (HIPAA/PCI/LGPD on your terms) ├─ Vendor lock-in: Eliminated (no cloud provider dependency) ├─ Scalability: Same as cloud (redundancy + load balancing) ├─ Security: Better (encrypted tunnel + your infrastructure) ├─ Competitive advantage: Early movers save 80% (permanent margin win) ├─ Why founders stick with cloud: Don't know self-hosting is viable ├─ Why founders choose self-hosted now: Understand cost + control ├─ Market shift: Inevitable (cost pressure = everyone migrates) └─ Question: Are you paying cloud bills you don't need to pay? (Time to decide)


Self-hosted agents via SSH tunnel = 80% cost reduction.

Current cloud agent costs

Typical monthly bill:

  • Compute: R$ 2K-10K (agent servers)
  • Database: R$ 500-2K (managed database)
  • Bandwidth: R$ 10-100 (data transfer)
  • Monitoring: R$ 400-2K (tools + observability)
  • Load balancer/API gateway: R$ 300-1K
  • Security (SSL, DDoS, WAF): R$ 400-3.5K
  • Miscellaneous: R$ 200-2K

Total: R$ 2.5K-20K/month (depending on scale)

Annual cost: R$ 30K-240K/year


Self-hosted costs are dramatically lower (same functionality).

Self-hosted infrastructure

Monthly cost:

  • Server rental: R$ 500-2K (dedicated server, much cheaper than cloud)
  • Monitoring: R$ 100-300 (open-source tools)
  • Maintenance: R$ 500-2K (your engineer time, amortized)
  • Miscellaneous: R$ 100-300

Total: R$ 1.2K-4.6K/month

Annual cost: R$ 14.4K-55K/year

Savings vs cloud: 60-80% reduction (R$ 30K-150K/year saved)


SSH tunneling makes self-hosted deployment simple (and secure).

How SSH tunnels work

Architecture:

  1. Your agent server creates outbound SSH connection (secure tunnel)
  2. External traffic routes through Nginx (reverse proxy)
  3. Nginx forwards to SSH tunnel (encrypts traffic automatically)
  4. Tunnel delivers traffic to your agent (on your infrastructure)
  5. Agent responds (same path back)

Network diagram:

External clients (HTTPS) ↓ Nginx reverse proxy ↓ SSH tunnel (encrypted) ↓ Your agent server

Benefits:

  • No open ports (NAT/firewall friendly)
  • Encrypted by default (SSH handles it)
  • Your infrastructure stays internal (no cloud dependency)
  • Clients don't know about your internal setup (completely hidden)

Conclusion: Self-hosted agents save 80% cost and give you complete control.

Latest developments show SSH tunneling makes self-hosted deployment simple.

Translation: You can deploy agents on-premises, pay 80% less, and control everything.

Why self-hosted matters:

  • SSH tunneling = simple + secure architecture
  • Cost savings = R$ 30K-500K+/year (depending on scale)
  • Data control = complete ownership (compliance advantage)
  • Vendor lock-in = eliminated (not dependent on cloud provider)
  • Operational burden = manageable (0.5-1 engineer, vs cloud infrastructure team)

Why founders still use cloud:

  • Myth: "Self-hosting is complicated" (False: SSH tunnel is simple)
  • Myth: "Self-hosting is less secure" (False: Encrypted tunnel is actually more secure)
  • Myth: "Self-hosting is less scalable" (False: Multi-server setup is standard)
  • Truth: Founders don't know self-hosting is viable (knowledge gap)

What to do:

  1. Assess current cloud bill (probably R$ 5K-20K/month)
  2. Calculate self-hosted cost (probably R$ 1.5K-5K/month)
  3. Understand SSH tunnel architecture (simple: 1-2 pages)
  4. Plan migration (2-4 weeks project)
  5. Deploy self-hosted setup (phased migration to reduce risk)
  6. Redirect savings to product development (or margins)

Estimated effort: 2-4 weeks (project-based)

Estimated payback: 1-3 months (savings cover setup cost)

Estimated ongoing savings: R$ 20K-400K/year (depending on scale)

Smart founders already calculating ROI (cost pressure = forced decision). Average founders still paying cloud bills (ignorance). Lazy founders complaining about costs (no action). Choose your path: Self-hosted efficiency or cloud convenience.


Stop paying for cloud you don't need. Deploy self-hosted agents via SSH tunnel.

If agent cost matters (and it does), the question is: How do you actually deploy self-hosted agents without becoming an ops expert?

Self-hosted agent deployment requires:

  • Dedicated server (cheap, ~R$ 500-2K/month)
  • SSH tunnel setup (simple, ~1-2 days)
  • Nginx reverse proxy (standard, ~1-2 days)
  • Agent deployment (Docker, ~1-2 days)
  • Database setup (PostgreSQL, ~1 day)
  • Monitoring + alerting (open-source, ~2-3 days)
  • CI/CD pipeline (automated deployment, ~2-3 days)
  • Network security (firewall, SSL, ~1-2 days)
  • Backup + disaster recovery (automated, ~1 day)
  • Team training (runbooks, ~1-2 days)
  • Testing + validation (verify everything works, ~3-5 days)
  • Incident response planning (prepare for failures, ~1-2 days)

OpenClaw helps you deploy self-hosted agents cost-effectively:

  • Infrastructure planning (server selection, sizing)
  • SSH tunnel architecture design (simple, proven patterns)
  • Nginx configuration (reverse proxy, load balancing)
  • Docker deployment (containerized agents, easy updates)
  • Database setup (PostgreSQL, backups, replication)
  • Monitoring + alerting (Prometheus, Grafana, notifications)
  • CI/CD pipeline (automatic deployment, testing)
  • Network security (firewall rules, SSL/TLS, DDoS protection)
  • Backup + disaster recovery (automated, tested procedures)
  • Team training (documentation, runbooks, procedures)
  • Cost optimization (identify waste, streamline operations)
  • Migration planning (phased transition from cloud)

Start self-hosting your agents → OpenClaw Self-Hosted Agent Deployment Framework

Because SSH tunneling proves it. Self-hosted agents are simple (not complicated). Cost savings are massive (80% reduction, R$ 30K-500K+/year). Deployment is manageable (2-4 week project). Control is complete (your infrastructure, your data). Early movers deploy self-hosted (lock in permanent cost advantage). Late movers pay cloud bills (permanent cost disadvantage). You have 1 week to calculate cloud bill. Spend 1 week planning self-hosted. Deploy over next 3 weeks. Realize savings immediately. Self-hosted = cost leadership = market advantage. Cloud = cost burden = margin pressure. Deploy now. Lead market.


Publicado em 5 de outubro de 2026

Leia também