Replace the Live Network Policy
Replace the live policy only when you cannot express the change as a NemoClaw preset. This workflow requires OpenShell 0.0.72+.
openshell policy set replaces the sandbox’s live policy with the file you provide. It does not
merge. A running policy contains the baseline plus every preset layered during onboarding and
later operations. Applying a file that contains only one part silently removes the other entries.
Export the Base Policy
Start from the current parsed base policy so the applied presets remain in the file:
The command retrieves and parses the base policy. It replaces literal credential values with [STRIPPED_BY_MIGRATION]. It exits nonzero instead of writing partial output when retrieval or validation fails. Do not use --raw because raw output retains the OpenShell metadata header.
Edit the Complete Policy
Edit current-policy.yaml. Add entries under network_policies and keep the existing version field. Preserve every baseline and preset entry that the sandbox still needs.
Do not apply a file that contains [STRIPPED_BY_MIGRATION]. Replace every marker with a supported
OpenShell credential binding or resolver placeholder; applying the marker as a literal value can
break credential delivery.
The openshell policy set command accepts a raw policy file. It does not accept a preset file that starts with a preset: metadata block. Use Apply Policy Presets when a maintained or custom preset can express the change.
Apply the Replacement
Apply the complete file:
The change applies to the running sandbox. OpenShell stores the replacement as the sandbox’s durable live policy. Update the baseline policy only when the change must apply to future sandboxes.
Verify the Result
Compare maintained presets with the current OpenShell policy:
Inspect the effective OpenShell policy before testing the endpoint:
Related Topics
- Create Custom Policy Presets applies scoped additions to the sandbox.
- Change the Baseline Network Policy changes every future sandbox.
- Approve or Deny Network Requests handles one-off access.