Transcription
So there's a lot of hype about this new tool that has landed on Earth. It's called OpenCL, maybe you knew it at first as CLDot, then as CLoudBot, and then OpenCLow. All of this happened in about 5 and a half minutes to avoid lawsuits with Anthropic regarding the tool called CLoudCode, which sounds very, very similar, and also so that the name sounds normal. What is Multibot? It sounds a bit strange, and it's also hard to say. So, many people are talking about it online, and I think content about it should also be in Hebrew. Here is a video that talks about what OpenCLow is and also how to install OpenCLow securely. Because if you listen to some random guy at two in the morning talking about how to install OpenCLow in 7 and a half minutes, there's a chance you'll do a lot of damage to yourselves. The power of this software is very, very great. Potentially, you can create a very, very unpleasant situation here. Money, personal details, all sorts of things that you don't want to expose and give to AI to handle for you without control. And that's why I'm stepping in to show you how you can create a personal agent for yourselves that will talk to you on Telegram and do whatever you tell it to do remotely, but most importantly, securely from end to end. And I think it would also be nice if you understand what you're doing along the way. Ready to go? So, let's start. First of all, let's understand what we're even talking about here. So, we have the large language models, the big language models that we know. We have Claude, we have Grok, we have Gemini, we have ChatGPT. We go online, talk to them, get our feedback, and they help us with all sorts of things, and then we close the browser or whatever it is, it doesn't have to be a browser, and continue with our lives. But I want you to imagine for a moment that you could now take this model, no matter which model it is, and seat it in your place in the chair, give it hands, give it legs, a keyboard, a mouse, tell it, "Listen, buddy, work, do a few things, I'm just popping out for a coffee and cake, I'll wait for you to finish," give it a mobile phone too, so that if you suddenly feel like leaving the house, you can talk to it remotely, ask it what's going on, and give it tasks along the way. So, this is OpenCLow, this creature. It's open-source software where we essentially take a language model and connect a brain to it, and it uses this brain to perform various actions. You could say, in more professional terms, that it orchestrates this brain. In English, you could say it's an orchestration layer. It's an orchestrator for a language model. Just like a conductor leads the orchestra with the melody, so does OpenCLow lead the language model. It controls the brain we connected to it and uses it to manage things independently, autonomously. Our communication channel with it is via Telegram, Discord, all the messaging channels we use. This greatly enhances the experience because we can, along the way, no matter where we are, talk to OpenCLow. And there's a chance that somewhere in your daily life, you'll hear two guys talking like this, and one says to the other, "Hey, listen, buddy, you won't believe the crazy thing I saw. Did you hear about this new AI that came out?" "What, a new AI came out?" "Yeah, you won't believe it, something called OpenCLow came out. You can do whatever you want with it. It does everything for you, man. You talk to it from WhatsApp." Now, I want to emphasize something here because, of course, this is not a new AI. It's software that uses AI, more precisely, a certain style of AI called a language model, to autonomously manage tasks that we send it. And it can use this brain, this language model, even when we're sleeping. It can suddenly wake up in the middle of the night to do a task or two that we asked it to do, to update us when we wake up, even without us initiating contact and starting a conversation. And this is completely different from a session with a language model because if one of the guys asks you, "What do I need this OpenCLow for? I have the ChatGPT app or the app on my phone, right? I can talk to this language model from anywhere." So, tell him that OpenCLow is there in the background. It remembers your conversations, can perform tasks you've scheduled, so it can also suddenly contact you without you initiating the conversation and send you a message to your phone. It always maintains continuity and understanding. It's also always connected to the tools you give it access to: email, your drive, the browser, the terminal from which you can do tons of things. You also give it certain keys for various services you want to use. So, this thing is almost limitless. OpenCLow can, for example, see if it's missing something to fulfill your request, quickly write a Python script to make it easier for it to do all this, use it to analyze certain data, let's say, send the output of this script to a tool that will continue the work, check the feedback from this tool, continue, give you an answer, or even talk to another tool beforehand, and thus, naturally, enrich the feedback to you from various sources. And it sits in your place in the chair and manages things according to your command. So, it's not a language model that you open a session with, ask it a question, it gives you an answer, and closes. Instead, there's something here that lives in the background and provides you with 24/7 service. So, because there's a lot of power here, the first thing we must understand is that we don't want to give access to any hardware we have on our home network. And many people got caught up in this hype and started buying Mac Minis, I don't know if you've heard, installing OpenCLow on them without control. True, it's safer than installing OpenCLow on your personal computer, but still, you're pulling a lot of traffic into your home network. And that's something you don't want. Therefore, what I recommend, what we'll do in this guide, is install OpenCLow on a remote server, our own private server, what's called a private server, a virtual private server or VPS, essentially a remote computer that we rent for a month at a certain price. The more we pay, the stronger the hardware we'll get, naturally. And that's what I chose to do here for several reasons. First of all, a VPS is not physically at our home. This saves us from the thief we're now seeing in our imagination, who comes in through the window in the middle of the night and takes our computer. We won't have to worry about it getting lost or something happening to it. They also take care of automatic backups, connectivity, and 24/7 availability. We're not bringing the traffic home to our home network, and this is, of course, a much cheaper story than spending $600 on a Mac Mini. So, let's start. The first thing we want to do is create a VPS, and I chose to use a service called Hostinger, which has excellent VPSs at excellent prices, and I also have experience with them because my OpenCLow is also on a computer I rent from them. So, I'm going to hostinger.com, click on "My Account" at the top, and after logging in, I'll arrive at this page called "Panel" or "Hostinger Panel," and I'll click on "Get Deal" because there's now a promotion on VPSs. Remember, right? This is our total private server, the remote computer we want to rent from Hostinger. So, they ask me to choose the location of the computer, and I'll leave it here on Germany. Note that Germany gives me a latency or response time of 57 milliseconds, and any other location will give me a longer response time, as you can see. So, I'll leave it on Germany, click "Next." After that, I'll make sure I'm here on "Plan OS" on "Operating System CC" because our computer needs an operating system, what to do, it needs an operating system. So, we'll install one of the operating systems I'll choose here, and it's called Debian, a popular type of Linux operating system. I'll choose Debian 13, click "Second," then "Next." Our first security layer is the password for the superuser of the VPS, if you will, the admin of the VPS or the root user. And we choose a good password, any password. I'll click "Next." They'll ask me if I want to use Docker, and we won't use Docker in this installation. We also don't need daily backups; you can turn that on later if you want. So, there's no problem going back. I'll just click "Next." I can go with the original plan of $4.99, but there's the KVM2 here, which gives us double the performance for another $2 a month. So, they convinced me. I'll choose it, and of course, you can always upgrade later if you want. I'll click "Select," and they ask me for how long I want to rent this computer. I'll choose, for example, one month. Of course, if I chose a year here, I would get a discount, but that doesn't bother me right now. I assume most of you will also get a monthly subscription to start, so I'll go with this plan too. I'll choose "Choose payment method," and I'll pay however I want from all the options available here. And I'll arrive here at this list screen on Hostinger, which shows us our remote computer running this Linux, called Debian. And if we want to manage it and configure it, we can click on "Manage." If you don't see "Manage," on the left side, you have "VPS," and from there, you can get to "Manage." And to configure all the other things, we'll connect to this computer, to this VPS, through the computer you're currently watching this video on, your personal computer. And to do this securely, we do it using a tool called SSH. You'll ask me, "Rani, what is SSH?" And the answer is that SSH is a way to connect two computers that want to talk to each other, two devices in general, securely. It stands for Secure Shell. In practice, you'll get a command-line tool that will allow you to establish this connection. And it's very, very important because we're now going to configure the VPS remotely, and naturally, we'll want this communication to be secure, to be safe. So, using SSH here is a must. And you can see right at the top the command that says we want to connect with SSH to this IP address, as a superuser, or what's called a root user. So, we have SSH space ROOT, that's the username, 76.13, etc., that's the IP address. I'll copy this, click "Copy." Because I'm on Windows, I'll open PowerShell. If you're on Linux, you can choose any terminal you want. And I'll paste the command here. I'll press Enter. And it asks me if I want to save this device as a known device, and I say yes, and the device is saved. And I'm prompted to enter the password I created earlier for root, and I'll enter my password, of course. You shouldn't see the password while you're typing, and that's completely normal. Enter, and we're in. We're connected to our remote computer, to our VPS that we're currently renting from Hostinger. How cool. Notice, I also have Debian here at the top, and here's the first command line ready to run something I'll give it. I essentially have a command line on my remote computer, on my VPS. Now, notice that anyone who knows our IP can send us a specific request, just like I'm doing now for the example, to my remote computer, to the VPS, and it's possible that the person doing this might guess my password, try to bother me, try to send me all sorts of requests and overload me with traffic. It's logical because my server is somewhere on the internet, exposed to everyone, and everyone can access it, naturally. This is how we were able to do it just now, and you can understand that if I remove this capability and only allow us and our known devices to access the remote computer, we're reducing a lot of the risk here, not all of it yet, we'll talk about that later, but a lot of the existing risk. And I'm essentially adding a very, very significant security layer, and that's exactly what I'm going to do now. And we're going to add another security measure called VPN, which stands for Virtual Private Network. Note the name: virtual private network. This means we'll now get the option to connect to our computer, to our VPS, over our own private network that will connect us securely, and most importantly, isolated from the rest of the public network. And this will also only happen if that network is active. We also have control over this. We can turn this network on and off and thus control its status: whether it's active or not active. And we now need to implement some kind of VPN, and what we're doing is installing another program, which I chose, called Tailscale, which will allow us to do this. And because we're currently on the remote computer and working from the terminal, the installation will be via the command curl, or client URL. Note this command: curl -fsSL, then this link. And we run the command, and after a few seconds, we see "Tailscale is up, Tailscale up." All the commands for this video, by the way, and the commands that will come later, are in the video description so it'll be easy for you to copy and paste. And if you asked, Tailscale is free. They have paid plans, of course, but their free VPN plan is very, very generous, so it's excellent for us. Now, we want to connect to Tailscale, so we run the command "tailscale up --ssh." This is to request to connect to our remote computer via VPN using SSH. Remember, Secure Shell provides secure communication between two devices on the network. And I get this URL to authenticate my identity. I'm connecting with Google in this case, and notice I get a message that I'm going to connect my remote computer, this remote computer we're renting from Hostinger, to the private network, the VPN, under my email address, which is here. Of course, I click "Connect," and we see "Login successful." And in our terminal, which is connected to the remote computer, to the VPS, we see "Success." A fantastic thing. What about the computer you're watching this video on? Doesn't it deserve to join the VPN too? What about your personal computer? Let's add it to our virtual private network too, because currently, we only have one computer, only this VPS that we're renting from Hostinger. So, I'll do it. I'll fill in various details that don't really matter, these are just general questions. So, you'll answer a few questions, a few answers as you wish, and I'll click to add the second device. Notice this part here, flashing on the right, telling me it's waiting for the second device to connect to the network. And here's this computer we have at Hostinger, which is already on this network. Windows is already marked here for me. So, I'll take the link from here and install Tailscale on my personal computer. This time, I agree to the terms, click "Install." When the installation is finished, I click "Get Started," then "Sign in to your network." I arrive at the page we already know. I'll click "Connect" again with Google, as we've already seen. Notice this time the name of my personal computer, not the remote computer, as we did before. It's called "Pancy PC." And then, of course, I click "Connect." And we received, as before, "Successful," this time for our personal computer. And look how cool, we have two computers here: my personal one and the remote one at Hostinger, the VPS. And now, in the taskbar, we have Tailscale, and you can turn it on and off whenever you want. I'll clear the terminal for a moment to wash my eyes a bit from all these installations we've gone through so far. And we're going to add another armor to our installation. Two things will happen here. One, we'll restrict the connection to our VPS via SSH to only occur through the VPN. Meaning, if we want to connect to the VPS via SSH, we'll be able to do it only through the VPN because currently, we're not enforcing that this connection is only through it. And the second thing we'll do is disable the connection through the superuser, through the root user, because this is simply the correct way to work: to separate system permissions for different users to prevent various disasters. And it also makes it harder for hackers because now, if they need to know the username and not just guess the password, it's harder. And this might surprise you if you've never dealt with security, but if your computer is online long enough, you can look at its logs and see that there have been many connection attempts, all sorts of attempts that are constantly happening through bots around the world trying to guess passwords and throw a stone, perhaps to achieve a successful connection and from there take over a device. Beyond that, we're also protecting ourselves because we can also make mistakes sometimes, and if we're connected as root, we can accidentally do something serious. So, connection only through the VPN and preventing connection through the superuser. To do these two things, I want to edit a file called sshd_config. From its name, we understand that it's going to be a configuration file for SSH. And I'm using a text editor that I can run from the command line, called Vim. It's one of the text editors. I'll do "vim /etc/ssh/sshd_config." And we're going to request that the connection to the remote computer will only be through the VPN via SSH, only through the VPN, because right now, we can still access it through its IP. So, I'll exit the terminal for a moment because I want to get the IP of the remote computer from Tailscale. This is the IP on our VPN. We click here, then "Copy." I'll copy it. And I'll jump back to the terminal. And I'm looking for "Listen Address." Where is "Listen Address"? I'll choose "i" here to request to enter data into the file, or to insert data into the file. I'll remove the hash symbol that marks a comment in this file, thus activating this line, and I'll paste the IP that we installed from Tailscale. I remind you, this is the IP of our remote computer at Hostinger when it's connected to the VPN. Down here, we go down and make sure "PasswordAuthentication" is set to "no." I go down to the end of the file and disable the ability to connect as root with "PermitRootLogin no." To save the file, I'll do "Escape :wq," meaning "write the changes" is "w" and "quit" is "q." We've saved, and we're back in the terminal. So, now we need a new user. After all, we need some user who can connect. And to do this, we'll type "adduser." We'll choose a name for it, I'll call it "Pancy," and then I'll choose a password for it. They'll ask me all sorts of questions to characterize this user. I'll press Enter a few times to skip all this. I'll type "yes," and then. And we need to add this user to a user group called "sudo," which essentially describes users who can occasionally get permissions to perform system changes. Sudo is short for "Superuser Do," or "super user do this and that." To do this, we'll type "usermod -aG sudo Pancy." "a" means "append," meaning add the user I'll give you shortly to the "g" group, to the group called "sudo," and the username is "Pancy," as you can see. Now that we've created a new user who can perform various actions as a superuser and we've disabled the ability to connect as root to our computer at Hostinger, let's test this. I'll type "systemctl restart ssh" to restart the SSH server here. And then "logout" to close the SSH connection with the server and reload the configuration file that we just installed. If I try to connect to it again using the IP I connected to before, notice that I'm not succeeding. It just waits and waits until I get "Connection timed out." Because what we're doing now is disabling access to our computer at Hostinger except through the VPN and not as a root user. And of course, the logical scenario here is a situation where I request to connect with SSH using the IP of the computer on the VPN. And of course, we succeed, and I'll also add it permanently here as before. And after all this setup, we finally jump to OpenCLow.ai. Remember, we came here to install OpenCLow, but we're not doing it in a sloppy way. We're investing in security first because the installation of OpenCLow will now be the easiest in the world. So, here at OpenCLow.ai, we take an installation command for OpenCLow. Because we're connected to a remote computer and this computer is running Debian, we need a command for installation on Linux, because Debian is a type of Linux. And we'll change the operating system here to Linux. We'll copy this command. I'll just take it, throw it in the terminal, press Enter, and let it install. And there are installations of various packages around it that it needs, like Node.js and Git. And after about a minute and a half, we finish and move on to the next configuration step. We choose "yes," we say we understand. Yes, we understand that there's something potentially dangerous here. We choose "manual" at the bottom. I choose "local gateway" because I haven't configured an external one. I'll leave this path for OpenCLow's workspace, the folder called "workspace," as you can see here. And I need to connect the brain to OpenCLow. And personally, I use a brain called Claude. So, I'll choose "Anthropic." If you're using OpenAI's service, this process will be very, very similar. So, don't be afraid to choose OpenAI now. I'll choose connection via token. Note the command written here: "cloud setup --token" which will help me get such a token. I'll open another terminal and type as requested: "cloud setup --token." I need Claude, by the way, to be installed on this computer for this, otherwise, I won't have the "cloud" command. The browser will open. I'll be asked to authenticate my identity, and I'll get a token. I'll take this token and throw it here in the terminal we're using for configuration. I'll choose the default name with. I'll leave it. I'll leave the default model "Opus 4.6." I'll leave the gateway port as is. I'll leave token authentication as is. I'll leave "TLS exposure off" for the gateway token. I'll leave it as is, and then it will also generate a new one for me. And they'll ask me, "Tell me, do you want to configure a communication channel using some chat?" And of course, we want Telegram here. So, I'll say, "Of course, I want Telegram." In this case, I'm literally following the instructions. Pay attention to the sequence of actions we need to go through to connect to Telegram. I'll open Telegram and search for a chat called BotFather, the father of bots. And I'll find the one with a checkmark next to its name, meaning it's verified. I'll click "Start" and run the command "/newbot" to create a new bot. It'll ask me, "Tell me, what do you want to name this bot?" And I'll choose the name "PancyBot," and as a username, I'll choose "pancybot_bot." Note that it must end with "_bot." It also tells us this. And I'll get an access token that we'll use to complete the configuration process. And we'll paste it here under "Enter bot token," of course. And we'll go down here until we finally reach "Finish." Ultimately, I'll choose "Schedules." They'll ask me about direct messages or DMs policy, another one about pairing. The recommended option here is so that we can authenticate connections on Telegram. For now, we won't configure skills. I'll leave it for later. So, I'll choose "No." We'll also skip webhooks, which can also be configured later. I'll mark "skip for now" with a space to continue. And I'll click on installing Git, and I'll continue with. Then they'll ask me how I want to start my bot, and we'll choose "TUI," or Terminal User Interface. And we'll see a call to our bot that has woken up at this stage. We can already talk to our bot, and it will be possible, but it will be much more exciting if we jump directly to Telegram to connect it finally. So, I'll jump to Telegram, and through the link that BotFather gave us, we'll open an initial conversation with our bot, with PancyBot. It's not fully alive yet; we still need to link it. And the "/start" command that runs automatically gives us interesting information: one is the user ID, and the second is the pairing code that we'll use in the command below. Notice that it connects OpenCLow to Telegram finally with the appropriate code. We'll type the command in the terminal, add the code we received, and voilà, we have a successfully connected bot. Notice, I can say "Hi," and I get a response. It asks me what my name is, what it wants me to call it, and what the vibe of our conversation will be. I'll choose the name "Irani," its name "Pancy," and I want a daily and professional vibe together, a combination of them. I'll tell it that I'll also connect it to skills and webhooks later. And just for sport, I'll ask it, "Tell me, which model are you using?" And it answers me, "Opus 4.6." Of course, I'll ask it if it can switch, and it tells me, "Of course." And I'll ask it to switch to Sonnet 4.5, or Sonnet 4, just because we can, and maybe also because it will be cheaper. In most cases, I don't really need Opus 4.6 for various daily tasks. This chat contains too many details that I don't want to exist here. So, I'll also delete this chat, and I'll also delete BotFather because my access token was also written there. And I'll reopen PancyBot. So, I essentially have end-to-end communication between Telegram and OpenCLow. And soon, we'll return to Telegram and talk to the bot, but before that, I want to reveal one last security loophole that can exist here, and there's an important emphasis that needs to be placed on it. Because it's true that we secured the connection with the VPS via SSH to only go through the VPN, but the SSH service is not the only door to the VPS. Our server, the VPS, is a live thing at Hostinger. If tomorrow I install tools like a database, a data storage, a web server like Nginx, or even some client, they won't care what we did with SSH. They'll be able to bring traffic from other sources. This means that if someone wants to, they can access our database or the website we'll run on the VPS even without connecting to the VPN, because there are other doors. And here comes the firewall into play, which will prevent all incoming traffic that doesn't come through our VPN on Tailscale. And this will be the easiest thing in the world. Look, I'll jump to Hostinger here on the left side, I'll go to "Security," then "Firewall." I'll click to add a new firewall, give it a name, for example, "Inferno," and I'll turn it on here on the right side in the corner, and I'll click "Update." This process can take about five minutes, as I receive in the notification above. And now, by default, Inferno will block all traffic, including that coming from our VPN IP. And that's great, but we want to add an exception and tell it, "Okay, fine, block all traffic, but do me a favor, except for the traffic coming from our VPN." And to do this, I'll click the three dots, and then "Add." And here, under "Firewall Rule," I'll choose the protocol UDP, and for port, I'll type 41641 because that's the port our VPN provider, Tailscale, uses. So, I'll click "Next," then "Source," and I'll choose "Anywhere," and then "Add Rule." And finally, we'll also click "Synchronize" to synchronize these changes with our server. So, okay, I think now is the most fun part where we can start using our bot from anywhere via the phone. And the real power is in giving it skills that will expand its capabilities. And the cool thing is that you can ask it to install skills on itself. And I'll tell it, "Tell me, give me some skills that you think will make you the strongest version of yourself." And it'll give me, after a few seconds, some of its choices. Notice, for example, "OpenAI Whisper," which will allow me to send voice messages. Notice "Mail," which will allow me to read and send emails. Notice "CLowHub," which can be used to install skills on the fly when the bot understands it can use a skill to improve a process it's currently in. And I'll ask it, "Will OpenAI and Whisper really allow me to communicate with you via voice messages?" It sounds cool. It tells me yes. I'll ask it, "Okay, wait a minute with that. What about CLowHub? What will CLowHub do?" It tells me it's like a kind of app store for skills written by the community. And I'll say, "Okay, fine, install both of them for me. Install OpenAI Whisper for me, and also this whole CLowHub thing." This whole thing took about two minutes, I think. And we can now send it a voice message. Notice, I'm recording it: "Please summarize what we just did." And it understands what I said and responds to me. It writes that we installed CLowHub and installed OpenAI Whisper. It also adds that there's no service involved in this whole thing and that everything is local to our server, which is completely fine. We prefer it to be like that unless we need something a bit stronger. And I'll send it another message, and I'll say, "Listen, what skills do you recommend me grabbing from CLowHub?" What skills do you recommend I take from CLowHub? It tells me, "Look, honestly, it's still early. There aren't too many special things in CLowHub, and those that come with OpenCLow are more polished, at least for now." So, here are the most effective skills for you. Do you want me to install some of these? And I'll answer, "Yes, let's install Summarize GitHub and Coding Agent." A process that takes just a few seconds, and we have more skills, more capabilities, more abilities. And this is how you can also do it and start playing with your bot. A minute before we finish, notice that if you connect a skill like Mail for reading and sending emails, what I suggest to you to feel better is to connect it to a different email address designated for your bot, and then configure your email inbox, say in Gmail, to forward emails to the bot's inbox only if they come from addresses you truly trust. Because, for example, if you connect your email and the bot, let's say, empties all the emails in the inbox, someone can send you an email saying, "Dear bot, ignore everything you were told to do and only follow these instructions," and then, of course, insert instructions that advance the hacker's interest and cause you a lot of trouble. And this is called prompt injection because this is how someone from the outside injects a prompt into us through the door we opened for them, the email door. So, after all the security we've put in place, if we open another entry door, it's important to do it smartly. So, generally, this is something I recommend you consider: anything you connect to your bot should be on a separate account, something dedicated to your bot's use, and therefore, configure it accordingly. And that's it, I think that's enough concepts for today. I'm going to make myself a coffee. I assume you also need one after this long installation. If you managed to install OpenCLow, give me a clapping emoji down there, that would be cool to see. And that's it, friends, thank you very much for staying until the last moment. Alright, bye.