~/.nemoclaw/config.json | Host-level CLI configuration and defaults created by onboarding or config commands. | Only if you want NemoClaw to forget host defaults and rebuild them on the next setup. |
~/.nemoclaw/credentials.json | Legacy plaintext credential file from earlier releases. Onboarding stages allowlisted values and registers them with the OpenShell gateway. After verified migration, it removes only unchanged migrated entries and preserves all others. It securely deletes the file when no entries remain. See Credential Storage for retained-file and empty-file cleanup behavior. | No; run nemohermes onboard to complete migration and cleanup so you do not lose a credential that is not yet registered with the gateway. |
~/.nemoclaw/sandboxes.json | Current sandbox registry used by nemohermes list, default sandbox selection, rebuild, and recovery commands. See Malformed Registry File when a command reports that this file is not valid JSON. | No. Deleting it makes the host forget existing sandboxes and can block state-preserving recovery. |
<selected-state-root>/onboard-session.json | Active onboarding session or rebuild recovery journal. Other sandboxes’ interrupted rebuilds can be retained separately. It can contain secret-free external component activation evidence bound to the sandbox identity fingerprint and lifecycle generation. | Do not delete it to resolve an interrupted rebuild. For an ordinary failed onboarding attempt, prefer nemohermes onboard --fresh when externalComponentActivation is absent. If that field is present, preserve the file, sandbox registry, and sandbox for an identity-verified recovery decision. Version 1 does not support resume or recovery for that activation state. |
<selected-state-root>/.onboard-rebuild-<sandbox>.json | Retained rebuild session for one sandbox. NemoClaw restores it to the active session when that sandbox rebuilds. | No. Rerun nemohermes <sandbox> rebuild with the same settings and preserve the recovery files. |
~/.nemoclaw/gateways/<port>/automatic-gateway-port.pending | Owner-only identity for an installer-selected alternate port whose onboarding is deferred or incomplete. When NEMOCLAW_GATEWAY_PORT is unset, the installer and CLI use this port so later or resumed onboarding and cleanup stay in the same state root. Successful installer-driven or direct CLI onboarding promotes it to automatic-gateway-port. | Preserve a valid marker; ordinary cleanup must use the reported gateway-scoped uninstall guidance. Fresh onboarding retains this automatic port and promotes it on success. If the resolver specifically reports an invalid automatic marker, inspect and remove only that invalid marker, or set NEMOCLAW_GATEWAY_PORT explicitly to target another environment. |
~/.nemoclaw/gateways/<port>/automatic-gateway-port | Owner-only completed identity for an installer-selected alternate port. When NEMOCLAW_GATEWAY_PORT is unset, later installer and CLI processes restore this port instead of using 8080. | Preserve a valid marker; uninstalling this gateway removes it with the port-scoped state. If the resolver specifically reports an invalid automatic marker, inspect and remove only that invalid marker, or set NEMOCLAW_GATEWAY_PORT explicitly to target another environment. |
~/.nemoclaw/usage-notice.json | Records the third-party software notice version in acceptedVersion and the acceptance time in acceptedAt. Install, onboarding, and rebuild flows consult this file and prompt again when its recorded version differs from the current notice or the file is absent. | Yes; deleting it makes the next applicable install, onboarding, or rebuild flow prompt for acceptance again. |
<selected-state-root>/bedrock-runtime-adapter.pid | Mode-0600 canonical PID for the selected gateway’s host-local Amazon Bedrock Runtime adapter. Uninstall correlates it with the lifecycle state and journal before it signals a process. | No while the adapter or an unfinished uninstall journal exists. Uninstall retires it only after it proves the recorded process is absent. |
<selected-state-root>/bedrock-runtime-adapter-token | Mode-0600 local bearer token that authenticates requests to the selected gateway’s Amazon Bedrock Runtime adapter. This token is separate from the upstream AWS credential held by the adapter process. | No while the adapter or an unfinished uninstall journal exists. Uninstall removes it only after process absence and lifecycle generation match the journal. |
<selected-state-root>/bedrock-runtime-adapter.json | Mode-0600 lifecycle state that binds the adapter generation, canonical PID, process start identity, current user, executable and launcher paths, adapter port, and token hash. It does not contain the bearer token. | No while the adapter or an unfinished uninstall journal exists. Keep it for fail-closed uninstall recovery. |
~/.local/state/nemoclaw-bedrock-runtime-adapter/<gateway-port>/uninstall.json | Mode-0600 per-gateway phase journal for Amazon Bedrock adapter cleanup. It remains outside the selected state root so an interrupted uninstall can resume the generation. Onboarding refuses to start another generation while this journal remains unfinished. | No. Rerun uninstall with the same gateway port and let successful cleanup retire the journal. |
~/.nemoclaw/ollama-proxy-token | Host-global auth token used by the host-side Ollama auth proxy. Every gateway port on the host uses this one file. | Yes, but rerun onboarding for every gateway port that uses Local Ollama afterward, because a new token invalidates the shared proxy for all of them. |
~/.nemoclaw/ollama-backend | Host-global legacy route URL used to restart the Ollama auth proxy and retained for compatibility with earlier releases. | No while any gateway uses the shared proxy. Rerun onboarding if this file is missing or damaged. |
~/.nemoclaw/ollama-backend.json | Mode-0600, versioned descriptor that identifies whether the matching legacy route fronts Ollama or a compatible endpoint. Recovery trusts its kind only when both files contain the same URL. | Yes, but recovery uses neutral remediation until onboarding recreates the descriptor. |
~/.nemoclaw/ollama-proxy-port | Host-global port used by the Ollama auth proxy and every Local Ollama sandbox route on the host. A command with a different NEMOCLAW_OLLAMA_PROXY_PORT stops before changing the shared proxy. | No while any gateway uses Local Ollama. Full uninstall uses this file to find the proxy and removes it with the other shared proxy state. |
~/.nemoclaw/dual-station-vllm-api-key | Owner-only host-global bearer API key shared by authenticated NemoClaw-managed vLLM profiles. | No while a managed vLLM runtime uses it. An eligible destroy removes it only after the authenticated single-host container is removed or confirmed absent and no registered vllm-local consumer remains. Preservation options and distributed ownership keep it. Full uninstall removes it only after matching runtime cleanup succeeds and no sibling gateway remains. |
~/.nemoclaw/host-local-vllm-runtime.json | Owner-only, credential-free receipt for a catalog-selected single-host vLLM runtime. It binds the immutable catalog, preset, and recipe digests to the container ID and API-key fingerprint. | No while that runtime exists. Recovery, destroy, and full uninstall fail closed if its profile labels do not match this receipt, and destroy or uninstall removes it only after container cleanup succeeds. |
~/.nemoclaw/host-local-vllm-pending-retirement.json | Owner-only, credential-free record of one eligible vllm-local sandbox name whose managed nemoclaw-vllm retirement is pending. Written before registry removal; a later eligible destroy replaces it. | No while retirement is pending. After registry removal, preserve it for a destroy retry with the same sandbox name. A settled retry clears the record, including when another vllm-local consumer remains, a distributed receipt owns the runtime, or --keep-vllm is requested. Full uninstall removes it with the other host-global state. |
~/.nemoclaw/managed-llama-cpp/api-key | Owner-only bearer API key mounted read-only into the managed llama.cpp container. It is absent from process arguments, logs, receipts, sandbox registry state, and status output. | No while the managed llama.cpp runtime exists. A retry reuses the same key. Destroy or full uninstall removes it only after runtime cleanup succeeds. |
~/.nemoclaw/managed-llama-cpp/owner.json | Owner-only, credential-free binding from one gateway to the sandbox, recipe, catalog digest, preset digest, and recipe digest that owns the managed llama.cpp runtime. | No while the managed llama.cpp runtime exists. Destroy or full uninstall removes it only after cleanup succeeds. |
~/.nemoclaw/managed-llama-cpp/receipt.json | Owner-only runtime receipt that binds the Docker authority, container ID, network, image digest, model identity, and lifecycle generation. It contains no API key. | No while the managed llama.cpp runtime exists. Recovery and cleanup use it and preserve it when ownership cannot be proved. |
~/.nemoclaw/managed-llama-cpp/runtime-provider-authority/host-local-inference.json | Owner-only, credential-free, write-once Docker endpoint and binding authority used to prove that resume and cleanup address the same container engine. | No while managed llama.cpp ownership exists. Recovery fails closed without this authority record. |
~/.nemoclaw/managed-llama-cpp/host-local-create-journal/ | Owner-only crash-recovery records for the managed llama.cpp create transaction. A retry reconciles an unfinished record before it starts another runtime. | No while managed llama.cpp ownership exists. Destroy or full uninstall removes it only after cleanup succeeds. |
~/.nemoclaw/managed-cluster-vllm-runtime.json | Owner-only host-global managed-cluster cleanup receipt. It contains no serving API key and binds the plan, ranked nodes, containers, and temporary discovery-claim identities. | No while the managed cluster exists. Full uninstall removes it after every container is removed. |
~/.nemoclaw/managed-cluster-vllm-runtime.json.rank-<rank>.ssh-binding/ | Owner-only copied SSH host-key and Docker-command binding needed to reach one recorded worker rank during full uninstall. | No while the managed cluster exists. Full uninstall removes every rank binding with the cleanup receipt after cluster cleanup succeeds. |
~/.nemoclaw/managed-cluster-managed-serving.json.<node-id>.ssh-binding/ | Owner-only host-global temporary SSH host-key and Docker-command claim written for one peer after setup confirmation and repeated topology qualification. Each claim is distinct from its durable runtime binding and applies to every gateway on the host. | Only after confirming that no setup transaction is active. Without a durable runtime receipt, an orphaned claim makes a new managed-vLLM install and full uninstall fail closed without mutation. With the matching host-global managed-cluster receipt, full uninstall retires every recorded claim after it removes every container. If claim retirement fails, it preserves the receipt for a retry. Gateway-scoped uninstall preserves each claim. |
~/.nemoclaw/dual-station-vllm-runtime.json | Owner-only host-global managed dual-Station cleanup receipt. It contains no serving API key and binds the peer, cluster, and GPU identities used to revalidate and remove both managed vLLM containers during full uninstall. | No while the managed pair exists. A full nemohermes uninstall removes the receipt after both containers are removed; gateway-scoped uninstall preserves it. |
~/.nemoclaw/dual-station-vllm-runtime.json.ssh-binding/ | Owner-only host-global copied SSH host-key and Docker-command binding needed to reach the recorded worker during full uninstall. | No while the managed pair exists. Full uninstall removes it with the cleanup receipt after pair cleanup succeeds; gateway-scoped uninstall preserves it. |