Change the Baseline Network Policy
Change the baseline policy when every future sandbox needs the same durable endpoint access. NemoClaw reads the policy from the host when it creates the sandbox.
Prerequisites
- Use a NemoClaw source checkout on the host.
- Keep the OpenShell CLI on your
PATH.
Make policy file changes on the host. The sandbox discards changes made only inside the sandbox when it is recreated.
Edit the Policy File
Open agents/hermes/policy-additions.yaml and add or modify endpoint entries.
Edit YAML manually when a maintained preset does not cover the required host, such as a reviewed public partner API.
Each entry in the network_policies section defines an endpoint group with these fields:
endpoints
: Host and port pairs that the sandbox can reach.
binaries
: Executables allowed to use the endpoint.
rules
: HTTP methods and paths that the endpoint permits.
allow_encoded_slash
: Allows percent-encoded slashes such as %2F in request paths.
Leave this field disabled unless the service uses encoded slashes in its documented route format, such as ClawHub scoped package names.
To include a maintained preset in the baseline policy, merge its network_policies entries into the applicable baseline file.
Use Apply Policy Presets when you need to add a preset to one running sandbox.
Re-Run Onboarding
Apply the updated baseline by running onboarding again:
The wizard reads the modified policy file and applies it to the sandbox.
Verify the Policy
Check that the sandbox is running with the updated policy:
Use nemohermes <name> policy-list to inspect the tracked preset state.
Use openshell policy get <name> when you need to inspect the effective OpenShell policy.
Related Topics
- Customize the Network Policy helps you choose the correct policy workflow.
- Create Custom Policy Presets adds durable access for one sandbox without changing the baseline.
- Network Policies explains the baseline policy schema and tiers.