Replace the Live Network Policy

View as Markdown

Replace the live policy only when you cannot express the change as a NemoClaw preset. This workflow requires OpenShell 0.0.72+.

openshell policy set replaces the sandbox’s live policy with the file you provide. It does not merge. A running policy contains the baseline plus every preset layered during onboarding and later operations. Applying a file that contains only one part silently removes the other entries.

Export the Base Policy

Start from the current parsed base policy so the applied presets remain in the file:

$nemohermes my-assistant policy get > current-policy.yaml

The command retrieves and parses the base policy. It replaces literal credential values with [STRIPPED_BY_MIGRATION]. It exits nonzero instead of writing partial output when retrieval or validation fails. Do not use --raw because raw output retains the OpenShell metadata header.

Edit the Complete Policy

Edit current-policy.yaml. Add entries under network_policies and keep the existing version field. Preserve every baseline and preset entry that the sandbox still needs.

Replace Redaction Markers

Do not apply a file that contains [STRIPPED_BY_MIGRATION]. Replace every marker with a supported OpenShell credential binding or resolver placeholder; applying the marker as a literal value can break credential delivery.

The openshell policy set command accepts a raw policy file. It does not accept a preset file that starts with a preset: metadata block. Use Apply Policy Presets when a maintained or custom preset can express the change.

Apply the Replacement

Apply the complete file:

$openshell policy set --policy current-policy.yaml --wait my-assistant

The change applies to the running sandbox. OpenShell stores the replacement as the sandbox’s durable live policy. Update the baseline policy only when the change must apply to future sandboxes.

Verify the Result

Compare maintained presets with the current OpenShell policy:

$nemohermes my-assistant policy list

Inspect the effective OpenShell policy before testing the endpoint:

$openshell policy get my-assistant