Run Sandboxes

View as Markdown

Use these workflows to keep existing sandboxes reachable and control the resources they consume.

Manage Dashboard Ports

If the forward stopped, or the installer reported that no active forward was found and the URL does not load, restart the forward manually with the port from the install summary.

$openshell forward start --background <dashboard-port> my-gpt-claw

On WSL, use 0.0.0.0:<dashboard-port> as the forward target so the Windows host can continue to reach the dashboard.

To list active forwards across all sandboxes, run the following command.

$openshell forward list

Run Multiple Sandboxes

Each sandbox needs its own dashboard port because openshell forward refuses to bind a port that another sandbox already uses.

Each Hermes sandbox also needs its own OpenAI-compatible API port. When another sandbox or a host listener already holds the default API port 8642, nemohermes onboard scans ports 8642 through 8652, uses the next free port, and records it for the sandbox.

If you intentionally run separate OpenShell gateways on the same host, set a different NEMOCLAW_GATEWAY_PORT before each onboarding run. NemoClaw isolates the gateway name and local state by port so one port-specific gateway does not replace another. A non-default NEMOCLAW_GATEWAY_PORT also gets its own host state root at ~/.nemoclaw/gateways/<port>/, with a separate sandbox registry, snapshots, and legacy credential-migration files, so gateway-scoped state stays segregated while shared host-level files remain under ~/.nemoclaw/. On first use after upgrading, NemoClaw moves legacy rows and related state only when their recorded gateway identity matches the selected port; ambiguous state is left untouched with remediation. Provider credentials remain in the OpenShell gateway store. The default port keeps the shared ~/.nemoclaw/ location. When other ports remain, nemohermes uninstall removes only the selected gateway and keeps the shared CLI, services, images, providers, configuration, models, and swap.

Gateway and dashboard cleanup is scoped by sandbox name and port. A later onboarding run that uses a different NEMOCLAW_GATEWAY_PORT or --control-ui-port does not tear down the first sandbox’s gateway or dashboard forward.

$nemohermes onboard # first sandbox uses 18789
$nemohermes onboard # second sandbox uses the next free port, such as 18790

To choose a specific port, pass --control-ui-port:

$nemohermes onboard --control-ui-port 19000

You can also set CHAT_UI_URL or NEMOCLAW_DASHBOARD_PORT before onboarding:

$CHAT_UI_URL=http://127.0.0.1:19000 nemohermes onboard
$NEMOCLAW_DASHBOARD_PORT=19000 nemohermes onboard

For port conflicts and overrides, refer to Port already in use.

Stop and Start a Sandbox

Stop a sandbox’s container to free CPU, memory, and GPU resources without losing anything:

$nemohermes <sandbox-name> stop

Workspace files, credentials, network policies, and the registry entry are preserved. The container stops running. After the container stops, NemoClaw attempts to stop that sandbox’s host dashboard forward. The shared host gateway and tunnel services keep serving other sandboxes.

Start it again later:

$nemohermes <sandbox-name> start

After Docker reports the existing container as running, NemoClaw waits for OpenShell to report the sandbox in the Ready or Running state. NemoClaw recovers missing agent processes and host forwards only after that phase, so a slow sandbox start does not need a separate recover command. Refer to nemohermes <name> stop and nemohermes <name> start for details. Use nemohermes <name> destroy when you want to delete the sandbox instead.

Manage the Cloudflare Tunnel

When the host has cloudflared, nemohermes tunnel start starts a Cloudflare tunnel. The tunnel can expose the forwarded Hermes endpoint with a public URL. Set CLOUDFLARE_TUNNEL_TOKEN before running the command when you want to use a Cloudflare named tunnel instead of a generated quick-tunnel URL.

$nemohermes tunnel start

nemohermes tunnel stop stops the tunnel but leaves the supervisor-owned in-sandbox gateway and agent-owned host forwards running for the selected or default sandbox.