Build2 publishers3 min readPublished
OpenClaw Enterprise borrows Kubernetes' control-plane split to govern persistent agents
OpenClaw's foundation released OpenClaw Enterprise, a free self-hosted control plane for persistent agents, on September 29 for internal pilots only. Workload authentication and gateway admission are unbuilt, so IT gets a design to test before 1.0 later in 2026.
The Engineer · Build desk

What happened
- Its control plane, OCC, deploys agents into isolated namespaces and manages their configuration, credentials, permissions and a record of changes made through it.
- OpenClaw's architecture documentation lists the API, console, persistent worker, PostgreSQL backend and Kubernetes packaging as already implemented.
- The project began at OpenAI, which donated it to the OpenClaw Foundation, and the foundation says Red Hat and NVIDIA have since helped develop it.
- The foundation describes itself as an independent 501(c)(3) nonprofit, and the project README says donors do not own or direct the project.
Compiled by The EngineerSomething wrong?How this is made
Why it matters
- constraint A security team can approve OCE's namespaces and permissions as written policy, but cannot yet treat a harness calling OCC as a verified identity.
- exposure Putting many agents' credentials and permissions behind one control plane makes OCC and its PostgreSQL store the component a pilot most needs to harden.
- decision IT teams whose policy is an outright ban can now run a self-hosted pilot, and have to decide whether pilot time is worth spending before the trust pieces arrive at 1.0.
"Think of it as Kubernetes for agents," runs the line The New Stack quotes in its coverage. The stated goal is a common layer for managing agents across different environments [12]. The comparison holds at the level of structure. I think the split is the right one for agents that keep state and take actions over time [22]. Policy lives in one place. Messages arrive at gateways, and harnesses run the agent turns, model calls and tool execution [5]. The repository describes the control-plane side as identities with role-based authorization, resource lifecycle management and audit events [21]. It deploys with Docker Compose for local development or with Kubernetes on internal infrastructure [20].
The weak point is the connection between those processes. In a split design, the control plane has to know that a gateway or harness calling it is one it admitted. Otherwise its permission records describe intent only. OpenClaw's architecture documentation lists external gateway admission, workload authentication back to OCC and some approaches to model authentication as unfinished [7].
OpenClaw released it early partly because it is unfinished. The aim is to let companies inspect and adapt the code, and to let outside developers shape it before the formal release [23]. Kevin Lin, a member of technical staff at OpenAI who leads the OCE work, set out the demand in a Tuesday blog post [10]. "The main feedback we hear from organizations is that a stronger common security, safety, and governance standard is needed before agents can be fully adopted," Lin wrote [8]. "As a consequence, the default stance of IT in most organizations is to ban agentic platforms like OpenClaw altogether." [9] The case that agents now need central governance rests on that account of customer feedback. The sources do not include an independent survey of IT policy. The named users so far are OpenAI and Red Hat, both testing the software internally [14].
The vendor-neutral claim is strongest in the design. Administrators are meant to be able to swap the harness, the model and the sandbox for third-party or internal alternatives [16]. The defaults are narrower. The getting-started guide asks for an OpenAI API key to deploy a first agent on the default model, with an override available [17]. RuntimeWire's reading is that this does not make the control plane OpenAI-only, since any agent still needs some model provider [18]. For a project that grew out of OpenAI, the default key is the least surprising line in the repository [13].
"OCE is built to run on your own infrastructure and will always be free for any organization to use," Lin wrote [11]. Only the license is free. Organizations still supply the infrastructure and the model access, and RuntimeWire notes they must judge whether the early-stage controls meet their own security requirements [19].
What to watch
- Whether workload authentication back to OCC and external gateway admission are finished before the 1.0 release planned for later in 2026.
- Whether the getting-started guide drops the OpenAI API key as the default path to a first agent.
- Whether organizations beyond OpenAI and Red Hat report OCE pilots, a direct test of Lin's claim that missing governance is what keeps agents banned.