在 Telegram 下令:部署上線+掃 port
案例摘要
Simon Roses 在樹莓派 5 跑 OpenClaw agent(AgentX),用 Telegram bot 指揮:部署最新版到 prod(正式環境只讀、只能開 PR、重啟服務要人工批准),還會從 VPS 經 SSH 跑 nmap 掃自己公網 IP 的開放 port,發現暴露的 gateway port 就告警並給防火牆指令。兩週 API 花費約 €50;偶爾卡住要人工介入。
實際結果
掃出暴露 port 並給修復指令;兩週 €50;偶發卡住。
台灣/大陸場景對照
🇹🇼 台灣
台灣 SOHO/接案維運:Telegram+最小權限+人工批准重啟,是居家機房的實用組合;prod 權限務必只讀起手。
🇨🇳 大陸
大陸輕量雲維運:同架構可接微信推送;注意公網暴露面,掃描先掃自己。
英文原文
Run production deploys and port scans from Telegram with OpenClaw
Simon Roses runs an OpenClaw agent, AgentX, on a Raspberry Pi 5 and talks to it through a Telegram bot. He asks it to deploy the latest changes to prod. It has read-only production access, can only open PRs, and needs his manual approval to restart services. It also runs nmap from a VPS over SSH to check his public IP for exposed ports, and alerts him on Telegram.
The agent ran port-exposure checks and flagged an example exposed gateway port, with a suggested firewall command. He reports about €50 in API spend after two weeks. It sometimes gets stuck and needs manual intervention.