Replace the Live Network Policy
Replace the live policy only when you cannot express the change as a NemoClaw preset. This workflow requires OpenShell 0.0.72+.
openshell policy set replaces the sandbox’s live policy with the file you provide.
It does not merge.
A running policy contains the baseline plus every preset layered during onboarding and later operations.
Applying a file that contains only one part silently removes the other entries.
Export the Base Policy
Start from the current round-trippable base policy so the applied presets remain in the file:
The command retrieves and validates the base policy.
It exits nonzero instead of writing partial output when retrieval or validation fails.
Do not use --raw because raw output retains the OpenShell metadata header.
Edit the Complete Policy
Edit current-policy.yaml.
Add entries under network_policies and keep the existing version field.
Preserve every baseline and preset entry that the sandbox still needs.
The openshell policy set command accepts a raw policy file.
It does not accept a preset file that starts with a preset: metadata block.
Use Apply Policy Presets when a maintained or custom preset can express the change.
Apply the Replacement
Apply the complete file:
The change applies to the running sandbox. For a durable source-of-truth change, update the baseline policy or record a custom preset with NemoClaw.
Verify the Result
Inspect the tracked preset state:
Inspect the effective OpenShell policy before testing the endpoint:
Related Topics
- Create Custom Policy Presets records scoped additions with the sandbox.
- Change the Baseline Network Policy changes every future sandbox.
- Approve or Deny Network Requests handles one-off access.