Create Custom Policy Presets
Create a custom preset when a sandbox needs a reviewed endpoint that no maintained NemoClaw preset covers. Custom presets add scoped access to one sandbox without changing the baseline policy.
Custom preset hosts bypass NemoClaw’s review process and can widen sandbox egress. Review every host before applying a custom preset, especially when the file originates outside your team.
Author a Preset
Create a preset-format YAML file:
The top-level preset.name must be a lowercase RFC 1123 label with letters, digits, and hyphens.
It must not collide with a maintained preset name such as slack or pypi.
Rename preset.name if NemoClaw reports a collision.
Each endpoint must name a specific host or a scoped subdomain wildcard such as *.example.com.
NemoClaw rejects catch-all destinations, including *, 0.0.0.0, 0.0.0.0/0, ::, and ::/0.
Rule matchers must match the endpoint protocol.
The same protocol-specific matcher shape applies to deny_rules.
User-authored presets must not declare allowed_ips for ordinary endpoints.
NemoClaw rejects that field in files passed through --from-file or --from-dir because it can widen the private ranges that OpenShell checks during SSRF protection.
Use hostnames, ports, protocols, methods, paths, and binary restrictions instead.
The only exception is the host.openshell.internal bridge endpoint for explicit sandbox-to-host service access.
Apply a Single File
Preview the file before you apply it:
NemoClaw records the complete YAML content with the sandbox. You can remove the preset later without keeping the original file.
Apply Every File in a Directory
Apply preset files in lexicographic order:
Processing stops at the first failure. NemoClaw does not remove presets that it already applied. Fix the failing file and run the command again to continue.
Add a Preset to the Source Catalog
Save a maintained local preset under nemoclaw-blueprint/policies/presets/.
The filename without .yaml must match preset.name.
The preset catalog reads preset.name, while policy-add <name> loads presets/<name>.yaml.
A mismatch can list a preset that the named command cannot load.
Apply the catalog preset by name:
Run the same command after editing the file. NemoClaw compares the preset with the live policy and applies changed content.
Remove a Custom Preset
Remove the preset by its recorded name:
Run nemoclaw <name> policy-list to see every maintained and custom preset recorded for the sandbox.
Configure a URL-Based MCP Server
Prefer the managed workflow in Add an MCP Server when the server uses authenticated HTTPS Streamable HTTP.
Use this custom policy recipe only for an agent-native URL registration that is outside the managed workflow.
Adding a URL such as https://mcp.example.com/mcp can cause a denied CONNECT tunnel.
The proxy returns HTTP 403 Forbidden when the target host is not in the default allowlist.
The related MCP client output contains this message:
This recipe applies only when URL-based MCP traffic uses the sandbox proxy and fails with this CONNECT response.
An OAuth MCP login failure such as getaddrinfo EAI_AGAIN is a different transport problem.
A direct-DNS path that bypasses the proxy is also a different problem.
Widening this allowlist does not fix either case.
Add the MCP host, exact Streamable HTTP route, required methods, and only the binary that opens the connection:
Streamable HTTP clients can use DELETE on the same endpoint to terminate a session.
Keep that method scoped to the exact MCP route.
Do not replace the route with /** unless the server contract requires every path.
Save the file as nemoclaw-blueprint/policies/presets/my-mcp.yaml.
Apply it by name:
NemoClaw previews the effective egress scope and prompts for confirmation before applying it. For a publicly routed host that passes SSRF checks, invoke the MCP tool again and confirm that the CONNECT tunnel succeeds.
The binaries list must include only the process that opens the connection.
The example assumes the Node runtime opens the MCP connection.
Replace the example path with the requesting binary that OpenShell reports in openshell term.
Shell-invoked clients need their own binary path, such as /usr/bin/curl.
Confirm a candidate path inside the sandbox:
A preset with an endpoint but no matching binary authorizes no process, so requests still fail.
OpenShell uses protocol: rest for this HTTP-based policy even though Streamable HTTP MCP carries JSON-RPC.
An allowlist entry does not disable OpenShell SSRF protection or create host routes. If the hostname resolves to a private, loopback, or link-local address, establish the required host or VPN route. Then follow the approved private-destination configuration. Refer to Agent cannot reach a host-side HTTP service for routing and private-destination diagnostics.
Related Topics
- Apply Policy Presets explains preset persistence and reapplication.
- Configure Raw TLS Passthrough covers endpoints that cannot use L7 inspection.
- Network Policies describes the policy schema.