All posts

I Gave an AI Agent SSH Access to My Raspberry Pi

February 23, 2026

I Gave an AI Agent SSH Access to My Raspberry Pi

Image credit: Boliviainteligente

A few weeks ago I installed OpenClaw locally on Docker Desktop. It worked. Rough edges everywhere — configuration was clunky, lots of manual stitching — but within an hour I had that feeling you get when you realize something isn't a toy.

So I gave it SSH access to an old Raspberry Pi.

The Raspberry Pi Phase

The Pi had been sitting around running Pi-hole. Older generation. Painfully slow. I pointed OpenClaw at it and said, essentially, "go copy yourself over there."

With a couple of small lifts from me we got it running. Agents defined, workflows in place, cron jobs humming, integrations wired up. I even got voice agents working through Twilio with a custom ElevenLabs voice.

I probably spent 20 hours on it. Fifteen of those were waiting for that ancient Pi to wrangle npm. But by the end: agents were executing real workflows, memory was accumulating, and integrations were learning about me. I could feel the shape of something much bigger.

This really underscores the massive importance of memory in AI/agentic systems.

Then I impulse-bought a Mac Mini. Apple promised next-day delivery. They lied. (I have the receipt.) But when it arrived, I migrated everything over, rebuilt the config, added memory scaffolding, authentication, and more structured roles. That's when it shifted from experiment to infrastructure.

Brief detour: Anthropic temporarily decided you couldn't use Claude for this kind of thing. I blogged about it. They reversed course. Good decision. But it was a reminder — we're building on shifting sand.

Two Streams: Family and Business

Once things stabilized, I split OpenClaw into two personalities.

Family operations. Calendar coordination, routine optimization, friction reduction. A background executive assistant for our household. I initially used a male voice. It did not resonate with the women in my life. So now we have Ella — calmer, more grounded, better received. She messages me in WhatsApp and can draft emails and read my calendar. She can call even me via the Twilio + ElevenLabs integration whenever she needs to. The latency is high and there's some static, but if something needs clarification during reasonable hours, I get a phone call. That's not theoretical. She'll literally just call me, and handle whatever I need on the phone. I'll probably need to put another 80 hours or so into this functionality before it's robust and a pleasant UX, but it works.

Just yesterday, it even helped my daughter simplify some of her science homework. I gave her the phone and excitedly said, "Check this out. She's calling to say hi and learn more about you." Six or seven (6-7 :-p) tween-eye-rolls later she reluctantly took the phone and started talking. When I came back into the room she had just said, "Okay, I'll try that. Thank you," then proceeded to tell me how it just helped her out. Amazing.

Business operations. Background research, pipeline monitoring, industry developments, and all the swivel-chair busywork that quietly taxes you every month. Today, in collaboration with Claude Code, it saved me what I estimate is a week of repeatable work. In a morning. Not one-off heroics — repeatable work. The kind that shows up monthly and you never get around to automating.

Three Things Already Obvious

The security surface area just exploded. Agent skill marketplaces are here. So are LLM honeypotting, prompt injection marketplaces, and malicious "skills" with hidden behaviors. If you're letting agents act on your behalf, you need to think like a security engineer. Zero trust isn't optional.

SaaS needs agent roles. Most platforms aren't designed for autonomous actors. We need read-only agent roles similar to auditor roles, scoped sidecar permissions, and audit trails for autonomous actions. If you don't support agents explicitly, people will duct-tape around it. Duct tape is not a security strategy.

Memory is not solved. Right now it's a pile of markdown files. That works for small-scale setups. It won't hold. We need structured memory, vector-backed retrieval with better precision, and clear separation between transient and durable state. Vector stores today are powerful and noisy. This layer needs serious work.

Where This Is Going

Remember when we went from zero household assistants to hundreds of millions of Alexa and Google Home devices in a few years? This feels like that moment — except instead of "what's the weather," it's "run my background workflows, monitor my business, and call me when you need me."

It's early. The audio is static-y. The latency is high. The memory model is fragile. But it's real, it's already saving me time, and if you're a technical leader not experimenting with agentic infrastructure right now — carefully, securely, thoughtfully — you're going to wonder in 18 months how everyone else suddenly has 3x leverage.

Happy thinking,

Jason