Customize the Sandbox Network Policy
Choose the policy workflow that matches the scope and persistence of the network access change. NemoClaw declares sandbox policy in YAML, and NVIDIA OpenShell enforces it at runtime.
If a sandbox needs an HTTP service on the host, expose the service on a host IP that the OpenShell gateway can reach.
Apply a custom preset with nemo-deepagents <sandbox> policy add --from-file.
For a private host, first pass --trusted-private-host <exact-host-or-ip> --dry-run and review the
generated address pins plus the binary, method, path, port, and access limits before applying the
same command without --dry-run.
Do not rely on host.docker.internal as a general host-service path because it bypasses the OpenShell policy path and may not be reachable.
Refer to Agent cannot reach a host-side HTTP service.
Adding a host to the egress policy permits a connection only when the endpoint, port, method, and
binary rules match. OpenShell applies SSRF protection separately. It can deny a request when the
final address resolves to a loopback, private, link-local, or blocked internal range. If a package
installer or browser download still fails after you allow the public host, install the binary at
build time. Use nemo-deepagents onboard --from instead of
runtime egress.
Static Changes
Static changes modify the policy source that NemoClaw reads during sandbox creation. Follow Change the Baseline Network Policy to edit the agent policy file, rerun onboarding, and verify the result.
Dynamic Changes
Dynamic changes update the OpenShell policy for a running sandbox. Use Apply Policy Presets for convenient reviewed additions. NemoClaw reads, modifies, writes, and verifies the live OpenShell policy without recording a second desired-policy state.
Use Approve or Deny Network Requests for one-off access. Use Replace the Live Network Policy only when a preset cannot express the complete change.
Policy Presets
Maintained policy presets cover common integrations and package services. Follow Apply Policy Presets to preview, apply, reapply, list, or remove them.
Review Network Policies for the maintained presets available to Deep Agents.
Custom Preset Files
Custom preset files add operator-reviewed endpoint access without changing the baseline. Follow Create Custom Policy Presets to author, validate, apply, and remove a custom preset.
Live Policy Replacement
OpenShell policy set replaces the current round-trippable OpenShell base policy. Follow Replace the Live Network Policy to export the parsed base policy, replace every [STRIPPED_BY_MIGRATION] marker, preserve existing entries, and apply a validated replacement. Provider-composed entries remain managed through their provider lifecycle rather than through the base-policy document.
Related Topics
- Network Policies is the canonical policy reference. - OpenShell Policy Schema provides the complete YAML schema. - OpenShell Sandbox Policies explains OpenShell-layer policy iteration.