Seu agent na nuvem custa caro. Self-hosted = 80% mais barato.
Self-hosted HTTP tunnels via SSH enable on-premises agent deployment. Cloud costs = suddenly optional. Your agents = no longer vendor lock-in.
Equipe OpenClaw · Time de Engenharia & Produto
A Equipe OpenClaw é formada por engenheiros, designers e especialistas em IA dedicados a construir a melhor plataforma de agentes conversacionais para negócios brasileiros. Combinamos expertise…
Seu agent na nuvem custa caro. Self-hosted = 80% mais barato.
Ontem publicação importante: Self-hosted HTTP tunnels com SSH + Nginx.
"HTTP tunneling via SSH = agents can communicate securely through firewalls (no port exposure). Translation: Deploy agents on your own infrastructure (on-premises, behind NAT, air-gapped networks). You don't need AWS/Google. You don't pay cloud bills. Vendor lock-in = broken."
What this means: Your agents can run on your servers, not cloud.
Why it matters: Cloud agent = R$ 10K-50K/month. On-premises agent = R$ 500-2K/month. 80%+ cost reduction.
Problem it reveals: Founders think "agent = must be cloud." Wrong. Self-hosted = now viable (and cheaper).
Você é founder.
Current reality (2026 - Cloud-only agent deployment, high costs):
YOUR CURRENT AGENT SETUP (Cloud-dependent, expensive):
├─ What self-hosted HTTP tunneling reveals:
│ ├─ Technology: SSH + Nginx can tunnel HTTP through secure channel
│ ├─ Implication: Agents don't need cloud infrastructure (AWS/GCP/Azure)
│ ├─ Deployment: Agents can run on-premises (your own servers)
│ ├─ Network: Works behind NAT/firewalls (no port exposure)
│ ├─ Cost: Dramatically lower (no cloud bills)
│ ├─ Vendor lock-in: Eliminated (not dependent on cloud provider)
│ ├─ Data sovereignty: Complete control (stays on your infrastructure)
│ └─ Compliance: Easier for regulated industries (HIPAA, PCI, LGPD)
│
├─ Your current cloud agent cost structure:
│ ├─ Cloud compute (agent servers):
│ │ ├─ Small agent (micro instance): R$ 200-500/month
│ │ ├─ Medium agent (standard instance): R$ 1K-3K/month
│ │ ├─ Large agent (high CPU): R$ 3K-10K/month
│ │ ├─ Very large agent (multiple instances): R$ 10K-50K+/month
│ │ └─ Your scenario: Probably R$ 2K-10K/month (dependent on scale)
│ │
│ ├─ Cloud database (agent data):
│ │ ├─ Managed database: R$ 500-2K/month (storage + backups)
│ │ ├─ Database scaling: R$ 1K-5K/month (if scaled)
│ │ └─ Your scenario: Add R$ 500-2K/month
│ │
│ ├─ Cloud bandwidth (agent requests):
│ │ ├─ Data transfer out: R$ 0.10 per GB
│ │ ├─ Normal agent: 100GB/month = R$ 10/month (negligible)
│ │ ├─ High-volume agent: 1TB/month = R$ 100/month (small)
│ │ └─ Your scenario: R$ 10-100/month (usually small)
│ │
│ ├─ Cloud monitoring/logging:
│ │ ├─ CloudWatch / Stackdriver: R$ 100-500/month
│ │ ├─ APM / error tracking: R$ 200-1K/month
│ │ ├─ Log storage: R$ 100-500/month
│ │ └─ Your scenario: R$ 400-2K/month (if doing it right)
│ │
│ ├─ Cloud load balancers / API gateways:
│ │ ├─ Application load balancer: R$ 200-500/month
│ │ ├─ API gateway: R$ 100-500/month
│ │ └─ Your scenario: R$ 300-1K/month
│ │
│ ├─ Cloud security (certificates, DDoS, WAF):
│ │ ├─ SSL certificate: R$ 100-500/month (managed)
│ │ ├─ DDoS protection: R$ 200-2K/month (optional but recommended)
│ │ ├─ Web Application Firewall: R$ 100-1K/month
│ │ └─ Your scenario: R$ 400-3.5K/month
│ │
│ ├─ Cloud storage (if agent stores files):
│ │ ├─ S3 / Cloud Storage: R$ 1-10/month (usually minimal)
│ │ └─ Your scenario: R$ 0-50/month
│ │
│ ├─ Miscellaneous / margin:
│ │ ├─ Unexpected charges: ~10% of total
│ │ └─ Your scenario: R$ 200-2K/month
│ │
│ └─ TOTAL MONTHLY COST:
│ ├─ Small agent: R$ 2.5K-6K/month
│ ├─ Medium agent: R$ 5K-15K/month
│ ├─ Large agent: R$ 15K-50K+/month
│ ├─ Annual cost: R$ 30K-600K/year (significant)
│ ├─ Assumption: You're paying because you think you MUST (cloud-only)
│ └─ Reality: You CAN deploy on-premises for 80%+ savings
│
├─ Self-hosted agent cost structure (on-premises via SSH tunnel):
│ ├─ Hardware investment:
│ │ ├─ Used server (Dell PowerEdge, HP ProLiant): R$ 2K-5K (one-time)
│ │ ├─ Co-location (if not in your office): R$ 300-1K/month
│ │ ├─ OR: Rent dedicated server (cheaper than cloud): R$ 500-2K/month
│ │ └─ Comparison: Cloud = R$ 5K/month recurring, Self-hosted = R$ 2K one-time + R$ 500/month
│ │
│ ├─ Network / connectivity:
│ │ ├─ SSH tunnel (secure, no port exposure): Free (built-in)
│ │ ├─ Nginx reverse proxy: Free (open-source)
│ │ ├─ SSL certificate (Let's Encrypt): Free (automated)
│ │ └─ Total networking: R$ 0-100/month (minimal)
│ │
│ ├─ Database (self-hosted):
│ │ ├─ PostgreSQL / MySQL (open-source): Free (software)
│ │ ├─ Disk storage: R$ 100-500/month (if rented co-lo)
│ │ ├─ Backups (automated): Free (script on same server)
│ │ └─ Total database: R$ 100-500/month (if co-located)
│ │
│ ├─ Monitoring / logging (self-hosted):
│ │ ├─ Prometheus (open-source monitoring): Free
│ │ ├─ Grafana (open-source dashboards): Free
│ │ ├─ ELK stack (open-source logging): Free
│ │ ├─ Disk for logs (100GB/month): R$ 100-300/month
│ │ └─ Total monitoring: R$ 100-300/month (minimal)
│ │
│ ├─ Maintenance / operations:
│ │ ├─ Your engineer time: 4-8 hours/month (R$ 1K-2K value)
│ │ ├─ Tools / automation: R$ 0-500/month (optional)
│ │ └─ Total operations: R$ 500-2.5K/month (depends on engineer cost)
│ │
│ └─ TOTAL MONTHLY COST (on-premises):
│ ├─ Server rental: R$ 500-2K/month
│ ├─ Monitoring: R$ 100-300/month
│ ├─ Maintenance: R$ 500-2K/month (your time)
│ ├─ Miscellaneous: R$ 100-300/month
│ ├─ Total: R$ 1.2K-4.6K/month
│ ├─ Comparison to cloud: 60-80% CHEAPER
│ ├─ Annual savings: R$ 30K-150K/year
│ └─ Investment payback: 1-3 months (if you have an engineer)
│
├─ FINANCIAL COMPARISON (Why self-hosted wins):
│ ├─ Scenario 1: Small SaaS (1 agent, 100 customers)
│ │ ├─ Cloud cost: R$ 3K/month = R$ 36K/year
│ │ ├─ Self-hosted cost: R$ 1.5K/month = R$ 18K/year
│ │ ├─ Savings: R$ 18K/year (50%)
│ │ ├─ Payback: 1 month (if using existing engineer)
│ │ └─ Conclusion: Self-hosted is obvious choice
│ │
│ ├─ Scenario 2: Medium SaaS (5 agents, 1000 customers)
│ │ ├─ Cloud cost: R$ 15K/month = R$ 180K/year
│ │ ├─ Self-hosted cost: R$ 3K/month = R$ 36K/year
│ │ ├─ Savings: R$ 144K/year (80%)
│ │ ├─ Payback: 2-3 weeks (one-time hardware investment)
│ │ └─ Conclusion: Self-hosted is financially compelling
│ │
│ ├─ Scenario 3: Large SaaS (20+ agents, 10K+ customers)
│ │ ├─ Cloud cost: R$ 50K+/month = R$ 600K+/year
│ │ ├─ Self-hosted cost: R$ 10K/month = R$ 120K/year
│ │ ├─ Savings: R$ 480K+/year (80%)
│ │ ├─ Payback: 1-2 weeks
│ │ ├─ Dedicated ops team: R$ 30K-50K/month (justified)
│ │ ├─ Total self-hosted: R$ 40-60K/month
│ │ ├─ Still cheaper than cloud by: R$ 200K-500K/year
│ │ └─ Conclusion: Self-hosted is strategically mandatory
│ │
│ ├─ Break-even analysis:
│ │ ├─ Initial self-hosted investment: R$ 5K-20K (one-time hardware)
│ │ ├─ Monthly savings: R$ 2K-40K (depending on scale)
│ │ ├─ Payback period: 2-10 days (for most SaaS)
│ │ ├─ Multi-year savings: R$ 100K-500K+ (very significant)
│ │ └─ Financial conclusion: Self-hosted ROI is obvious
│ │
│ └─ Why founders still use cloud (misconceptions):
│ ├─ Myth 1: "Self-hosting is complicated"
│ │ ├─ Reality: SSH tunnel + Nginx = simple (documented)
│ │ ├─ Learning curve: 1-2 days for competent engineer
│ │ └─ Complexity vs cost savings: Easy trade-off
│ │
│ ├─ Myth 2: "Self-hosting is less secure"
│ │ ├─ Reality: SSH tunnel = encrypted (actually more secure)
│ │ ├─ Your control: Complete (vs cloud provider's policies)
│ │ ├─ Data sovereignty: Complete (vs cloud provider's access)
│ │ └─ Security vs cost: Better security + lower cost
│ │
│ ├─ Myth 3: "Self-hosting is less scalable"
│ │ ├─ Reality: Multi-server setup = easily scalable
│ │ ├─ Load balancing: Simple (Nginx does this)
│ │ ├─ Database replication: Available (PostgreSQL/MySQL)
│ │ └─ Scalability vs cost: 10x better cost + same scalability
│ │
│ ├─ Myth 4: "Self-hosting requires operations team"
│ │ ├─ Reality: Most operations = automated (cron, scripts)
│ │ ├─ Team size: 0.5-1 engineer (vs cloud infrastructure engineers)
│ │ ├─ Cost of operations: R$ 500-2K/month (vs paying cloud bills)
│ │ └─ Operations vs cost: Smaller team + lower cost
│ │
│ ├─ Myth 5: "Self-hosting means no uptime SLA"
│ │ ├─ Reality: You control your infrastructure
│ │ ├─ Reliability: Can be 99.9%+ (with redundancy)
│ │ ├─ Backup/recovery: Simpler (no cloud vendor dependency)
│ │ └─ Reliability vs cost: Better control + lower cost
│ │
│ ├─ Myth 6: "I need cloud for compliance"
│ │ ├─ Reality: Compliance = audit trail + controls (you implement)
│ │ ├─ HIPAA/PCI/LGPD: Possible on self-hosted (with setup)
│ │ ├─ Data residency: Guaranteed (on your servers)
│ │ └─ Compliance vs cost: Better compliance + lower cost
│ │
│ └─ Truth: Most founders avoid self-hosting = lack knowledge
│ ├─ Solution: SSH tunneling proves it's simple
│ ├─ Implementation: 1-2 weeks to deploy
│ ├─ Savings realization: Immediate (within 1-3 months)
│ └─ Competitive advantage: Early movers lock in 80% cost reduction
│
├─ HOW TO DEPLOY SELF-HOSTED AGENTS (SSH tunneling architecture):
│ ├─ Architecture overview (high-level):
│ │ ├─ Your agents: Run on your infrastructure (on-premises/dedicated server)
│ │ ├─ SSH tunnel: Secure encrypted channel from agent to outside
│ │ ├─ Nginx reverse proxy: Sits between tunnel + external clients
│ │ ├─ Clients: Connect to Nginx (which routes to your agents via tunnel)
│ │ ├─ Result: Your agents are accessible externally (no port exposure)
│ │ ├─ Security: Encrypted tunnel (SSH) + no open ports (NAT-friendly)
│ │ └─ Network diagram:
│ │
│ │ [Your agents on your server]
│ │ ↓
│ │ [SSH tunnel]
│ │ ↓
│ │ [Nginx reverse proxy]
│ │ ↓
│ │ [External clients]
│ │
│ │
│ ├─ Step 1: Get infrastructure
│ │ ├─ Option A: Dedicated server (OVH, Linode, DigitalOcean)
│ │ │ ├─ Cost: R$ 500-1.5K/month (VPS is cheaper than cloud app hosting)
│ │ │ ├─ Setup: 15 minutes (pre-configured Linux)
│ │ │ ├─ Advantage: Control + simplicity
│ │ │ └─ Recommendation: Best for most SaaS
│ │ │
│ │ ├─ Option B: Your own hardware
│ │ │ ├─ Cost: R$ 2K-5K (one-time) + R$ 100-300/month (co-location)
│ │ │ ├─ Setup: 1-2 days (if not already in data center)
│ │ │ ├─ Advantage: Own hardware = no landlord dependency
│ │ │ └─ Recommendation: Good if you have hardware already
│ │ │
│ │ └─ Option C: Cloud servers (still cheaper than app hosting)
│ │ ├─ Cost: R$ 300-1K/month (bare metal instance)
│ │ ├─ Setup: 5 minutes (cloud console)
│ │ ├─ Advantage: Ease of cloud provisioning
│ │ └─ Recommendation: Good if already using cloud (better to use dedicated server)
│ │
│ ├─ Step 2: Set up SSH tunnel (reverse port forwarding)
│ │ ├─ Concept: Your agent server creates outbound SSH connection
│ │ │ ├─ Local side: Agent server (port 8080)
│ │ │ ├─ Remote side: Tunnel endpoint (Nginx server)
│ │ │ ├─ Tunnel direction: Reverse (server initiates, stays open)
│ │ │ └─ Result: External clients connect to Nginx, traffic routes through tunnel to agents
│ │ │
│ │ ├─ Command (on agent server):
│ │ │ ├─ ssh -R 8080:localhost:5000 tunnel@example.com
│ │ │ ├─ Explanation:
│ │ │ │ ├─ -R = reverse port forwarding
│ │ │ │ ├─ 8080 = port on remote (Nginx) machine
│ │ │ │ ├─ localhost:5000 = agent's local address (where agent listens)
│ │ │ │ ├─ tunnel@example.com = SSH server (Nginx host)
│ │ │ └─ Result: Remote port 8080 → SSH tunnel → Local agent (port 5000)
│ │ │
│ │ ├─ Make persistent (autorestart on disconnect):
│ │ │ ├─ Tool: autossh (manages SSH connection reliability)
│ │ │ ├─ Command: autossh -M 0 -R 8080:localhost:5000 tunnel@example.com
│ │ │ ├─ Systemd service: Ensure tunnel restarts on reboot
│ │ │ └─ Result: Tunnel always available (automatic recovery)
│ │ │
│ │ └─ Security considerations:
│ │ ├─ SSH key: Use key-based auth (no passwords, more secure)
│ │ ├─ Firewall: Restrict tunnel port to Nginx server only
│ │ ├─ Keep-alive: Enable SSH keep-alive (prevent timeout)
│ │ └─ Monitoring: Alert if tunnel disconnects (automatic failover)
│ │
│ ├─ Step 3: Set up Nginx as reverse proxy
│ │ ├─ Nginx role: Sits on tunnel endpoint, routes external traffic to agent
│ │ │ ├─ External clients: Connect to Nginx (example.com:443 HTTPS)
│ │ │ ├─ Nginx local: Forwards to tunnel (localhost:8080)
│ │ │ ├─ Tunnel: Encrypts + routes to agent server
│ │ │ ├─ Agent: Receives request, responds
│ │ │ ├─ Return path: Agent → Tunnel → Nginx → Client
│ │ │ └─ Result: Seamless communication (client unaware of tunnel)
│ │ │
│ │ ├─ Nginx config (simplified):
│ │ │ nginx
│ │ │ server {
│ │ │ listen 443 ssl;
│ │ │ server_name agent.example.com;
│ │ │ ssl_certificate /etc/letsencrypt/live/...;
│ │ │ ssl_certificate_key /etc/letsencrypt/live/...;
│ │ │
│ │ │ location / {
│ │ │ proxy_pass http://localhost:8080; # Forward to SSH tunnel
│ │ │ proxy_set_header Host $host;
│ │ │ proxy_set_header X-Real-IP $remote_addr;
│ │ │ }
│ │ │ }
│ │ │
│ │ │
│ │ ├─ SSL/TLS certificate: Use Let's Encrypt (free, automated)
│ │ │ ├─ Tool: Certbot (automatic certificate management)
│ │ │ ├─ Command: certbot --nginx -d agent.example.com
│ │ │ ├─ Renewal: Automatic (Certbot handles it)
│ │ │ └─ Cost: Free (no vendor lock-in)
│ │ │
│ │ ├─ Load balancing (if multiple agents):
│ │ │ ├─ Nginx upstream: Round-robin across multiple agent tunnels
│ │ │ ├─ Failover: Automatically skip failed agents
│ │ │ ├─ Health checks: Monitor agent availability
│ │ │ └─ Result: High availability (agent failure = automatic failover)
│ │ │
│ │ └─ Performance tuning:
│ │ ├─ Connection pooling: Reuse connections (reduce overhead)
│ │ ├─ Buffering: Disable if not needed (reduce latency)
│ │ ├─ Gzip compression: Enable (reduce bandwidth)
│ │ └─ Caching: Nginx can cache responses (if applicable)
│ │
│ ├─ Step 4: Deploy agent code (on your server)
│ │ ├─ Agent runtime: Use Docker (simplifies deployment)
│ │ │ ├─ Docker image: Build image with your agent code
│ │ │ ├─ Container: Run agent in container (port 5000)
│ │ │ ├─ Volumes: Mount config / data directories
│ │ │ ├─ Network: Expose port 5000 (localhost only)
│ │ │ └─ Orchestration: Docker Compose (simple) or Kubernetes (complex)
│ │ │
│ │ ├─ Database (self-hosted on same server or separate):
│ │ │ ├─ PostgreSQL / MySQL: Container or native install
│ │ │ ├─ Connection: Agent connects to DB (localhost or IP)
│ │ │ ├─ Backups: Automated (cron job → S3 / object storage)
│ │ │ └─ Monitoring: Database health checks
│ │ │
│ │ ├─ Logging / monitoring:
│ │ │ ├─ Agent logs: Centralize to stdout (Docker captures)
│ │ │ ├─ Log aggregation: ELK / Loki (optional, open-source)
│ │ │ ├─ Metrics: Prometheus (open-source)
│ │ │ ├─ Dashboards: Grafana (visualize metrics)
│ │ │ └─ Alerts: Send to Slack / email on issues
│ │ │
│ │ └─ CI/CD pipeline:
│ │ ├─ Git push: Trigger deployment
│ │ ├─ Build: Docker image build
│ │ ├─ Test: Run test suite
│ │ ├─ Deploy: Pull image, restart container
│ │ └─ Result: New agent versions deploy automatically
│ │
│ ├─ Step 5: Set up monitoring + alerting
│ │ ├─ Tunnel health:
│ │ │ ├─ Check if SSH tunnel is connected
│ │ │ ├─ Alert if tunnel drops
│ │ │ ├─ Auto-restart on failure (systemd or watchdog script)
│ │ │ └─ Test: Kill tunnel, verify automatic recovery
│ │ │
│ │ ├─ Agent health:
│ │ │ ├─ HTTP health check (agent responds to /health)
│ │ │ ├─ Nginx checks agent status regularly
│ │ │ ├─ Alert if agent is down
│ │ │ ├─ Auto-restart if needed
│ │ │ └─ Test: Kill agent, verify automatic recovery
│ │ │
│ │ ├─ Performance monitoring:
│ │ │ ├─ Response time: Alert if slow (>1s)
│ │ │ ├─ Error rate: Alert if >1% errors
│ │ │ ├─ Resource usage: Alert if CPU/memory high
│ │ │ ├─ Database performance: Monitor query latency
│ │ │ └─ Dashboard: Real-time visibility (Grafana)
│ │ │
│ │ └─ Alerting channels:
│ │ ├─ Slack: Instant notifications for team
│ │ ├─ Email: Backup alerts
│ │ ├─ PagerDuty: On-call escalation (if high severity)
│ │ └─ SMS: Critical alerts only (avoid noise)
│ │
│ └─ Total setup time: 2-4 weeks
│ ├─ Infrastructure setup: 1-2 days
│ ├─ SSH tunnel + Nginx: 1-2 days
│ ├─ Agent deployment: 2-3 days
│ ├─ Monitoring setup: 2-3 days
│ ├─ Testing + validation: 3-5 days
│ ├─ Team training: 1-2 days
│ └─ Total: 2-4 weeks (manageable project)
│
├─ COMPARING CLOUD VS SELF-HOSTED (Decision matrix):
│ ├─ Cost: Self-hosted wins (80% cheaper)
│ ├─ Time to deploy: Cloud wins (days vs weeks)
│ ├─ Operational overhead: Cloud wins (managed for you)
│ ├─ Data control: Self-hosted wins (complete ownership)
│ ├─ Compliance: Self-hosted wins (data residency)
│ ├─ Vendor lock-in: Self-hosted wins (no dependency)
│ ├─ Scalability: Tie (both scalable, different trade-offs)
│ ├─ Security: Self-hosted wins (you control)
│ ├─ Flexibility: Self-hosted wins (customize anything)
│ └─ Recommendation:
│ ├─ Choose CLOUD if: Quick MVP (days matter) + can afford cost
│ ├─ Choose SELF-HOSTED if: Cost matters + can wait 2-4 weeks
│ ├─ Hybrid: Start cloud (quick), migrate self-hosted (reduce cost)
│ └─ For most SaaS: Self-hosted ROI is obvious (do it)
│
└─ THE BOTTOM LINE:
├─ SSH tunneling: Enables secure agent deployment (on-premises, no open ports)
├─ Self-hosting option: Now viable (previously thought impossible)
├─ Cost reduction: 60-80% cheaper than cloud (R$ 30K-500K+/year savings)
├─ Timeline: 2-4 weeks to deploy (manageable project)
├─ Operational overhead: 0.5-1 engineer (vs cloud infrastructure team)
├─ Data control: Complete (you own + control everything)
├─ Compliance: Easier (HIPAA/PCI/LGPD on your terms)
├─ Vendor lock-in: Eliminated (no cloud provider dependency)
├─ Scalability: Same as cloud (redundancy + load balancing)
├─ Security: Better (encrypted tunnel + your infrastructure)
├─ Competitive advantage: Early movers save 80% (permanent margin win)
├─ Why founders stick with cloud: Don't know self-hosting is viable
├─ Why founders choose self-hosted now: Understand cost + control
├─ Market shift: Inevitable (cost pressure = everyone migrates)
└─ Question: Are you paying cloud bills you don't need to pay? (Time to decide)
Self-hosted agents via SSH tunnel = 80% cost reduction.
Current cloud agent costs
Typical monthly bill:
- Compute: R$ 2K-10K (agent servers)
- Database: R$ 500-2K (managed database)
- Bandwidth: R$ 10-100 (data transfer)
- Monitoring: R$ 400-2K (tools + observability)
- Load balancer/API gateway: R$ 300-1K
- Security (SSL, DDoS, WAF): R$ 400-3.5K
- Miscellaneous: R$ 200-2K
Total: R$ 2.5K-20K/month (depending on scale)
Annual cost: R$ 30K-240K/year
Self-hosted costs are dramatically lower (same functionality).
Self-hosted infrastructure
Monthly cost:
- Server rental: R$ 500-2K (dedicated server, much cheaper than cloud)
- Monitoring: R$ 100-300 (open-source tools)
- Maintenance: R$ 500-2K (your engineer time, amortized)
- Miscellaneous: R$ 100-300
Total: R$ 1.2K-4.6K/month
Annual cost: R$ 14.4K-55K/year
Savings vs cloud: 60-80% reduction (R$ 30K-150K/year saved)
SSH tunneling makes self-hosted deployment simple (and secure).
How SSH tunnels work
Architecture:
- Your agent server creates outbound SSH connection (secure tunnel)
- External traffic routes through Nginx (reverse proxy)
- Nginx forwards to SSH tunnel (encrypts traffic automatically)
- Tunnel delivers traffic to your agent (on your infrastructure)
- Agent responds (same path back)
Network diagram:
External clients (HTTPS) ↓ Nginx reverse proxy ↓ SSH tunnel (encrypted) ↓ Your agent server
Benefits:
- No open ports (NAT/firewall friendly)
- Encrypted by default (SSH handles it)
- Your infrastructure stays internal (no cloud dependency)
- Clients don't know about your internal setup (completely hidden)
Conclusion: Self-hosted agents save 80% cost and give you complete control.
Latest developments show SSH tunneling makes self-hosted deployment simple.
Translation: You can deploy agents on-premises, pay 80% less, and control everything.
Why self-hosted matters:
- SSH tunneling = simple + secure architecture
- Cost savings = R$ 30K-500K+/year (depending on scale)
- Data control = complete ownership (compliance advantage)
- Vendor lock-in = eliminated (not dependent on cloud provider)
- Operational burden = manageable (0.5-1 engineer, vs cloud infrastructure team)
Why founders still use cloud:
- Myth: "Self-hosting is complicated" (False: SSH tunnel is simple)
- Myth: "Self-hosting is less secure" (False: Encrypted tunnel is actually more secure)
- Myth: "Self-hosting is less scalable" (False: Multi-server setup is standard)
- Truth: Founders don't know self-hosting is viable (knowledge gap)
What to do:
- Assess current cloud bill (probably R$ 5K-20K/month)
- Calculate self-hosted cost (probably R$ 1.5K-5K/month)
- Understand SSH tunnel architecture (simple: 1-2 pages)
- Plan migration (2-4 weeks project)
- Deploy self-hosted setup (phased migration to reduce risk)
- Redirect savings to product development (or margins)
Estimated effort: 2-4 weeks (project-based)
Estimated payback: 1-3 months (savings cover setup cost)
Estimated ongoing savings: R$ 20K-400K/year (depending on scale)
Smart founders already calculating ROI (cost pressure = forced decision). Average founders still paying cloud bills (ignorance). Lazy founders complaining about costs (no action). Choose your path: Self-hosted efficiency or cloud convenience.
Stop paying for cloud you don't need. Deploy self-hosted agents via SSH tunnel.
If agent cost matters (and it does), the question is: How do you actually deploy self-hosted agents without becoming an ops expert?
Self-hosted agent deployment requires:
- Dedicated server (cheap, ~R$ 500-2K/month)
- SSH tunnel setup (simple, ~1-2 days)
- Nginx reverse proxy (standard, ~1-2 days)
- Agent deployment (Docker, ~1-2 days)
- Database setup (PostgreSQL, ~1 day)
- Monitoring + alerting (open-source, ~2-3 days)
- CI/CD pipeline (automated deployment, ~2-3 days)
- Network security (firewall, SSL, ~1-2 days)
- Backup + disaster recovery (automated, ~1 day)
- Team training (runbooks, ~1-2 days)
- Testing + validation (verify everything works, ~3-5 days)
- Incident response planning (prepare for failures, ~1-2 days)
OpenClaw helps you deploy self-hosted agents cost-effectively:
- Infrastructure planning (server selection, sizing)
- SSH tunnel architecture design (simple, proven patterns)
- Nginx configuration (reverse proxy, load balancing)
- Docker deployment (containerized agents, easy updates)
- Database setup (PostgreSQL, backups, replication)
- Monitoring + alerting (Prometheus, Grafana, notifications)
- CI/CD pipeline (automatic deployment, testing)
- Network security (firewall rules, SSL/TLS, DDoS protection)
- Backup + disaster recovery (automated, tested procedures)
- Team training (documentation, runbooks, procedures)
- Cost optimization (identify waste, streamline operations)
- Migration planning (phased transition from cloud)
Start self-hosting your agents → OpenClaw Self-Hosted Agent Deployment Framework
Because SSH tunneling proves it. Self-hosted agents are simple (not complicated). Cost savings are massive (80% reduction, R$ 30K-500K+/year). Deployment is manageable (2-4 week project). Control is complete (your infrastructure, your data). Early movers deploy self-hosted (lock in permanent cost advantage). Late movers pay cloud bills (permanent cost disadvantage). You have 1 week to calculate cloud bill. Spend 1 week planning self-hosted. Deploy over next 3 weeks. Realize savings immediately. Self-hosted = cost leadership = market advantage. Cloud = cost burden = margin pressure. Deploy now. Lead market.
Publicado em 5 de outubro de 2026