Customize the Sandbox Network Policy

View as Markdown

Choose the policy workflow that matches the scope and persistence of the network access change. NemoClaw declares sandbox policy in YAML, and NVIDIA OpenShell enforces it at runtime.

GoalUse this workflow
Change every future sandbox for an agentChange the Baseline Network Policy
Add or remove a maintained preset for one sandboxApply Policy Presets
Add an operator-reviewed endpoint that no maintained preset coversCreate Custom Policy Presets

| Allow direct TLS negotiation for an exact endpoint | Configure Raw TLS Passthrough | | Replace the complete live policy | Replace the Live Network Policy | | Give the sandbox agent a redacted policy summary | Explain Network Policy to Agents | | Approve or deny one blocked request | Approve or Deny Network Requests |

If a sandbox needs an HTTP service on the host, expose the service on a host IP that the OpenShell gateway can reach. Apply a custom preset with nemoclaw <sandbox> policy add --from-file. For a private host, first pass --trusted-private-host <exact-host-or-ip> --dry-run and review the generated address pins plus the binary, method, path, port, and access limits before applying the same command without --dry-run. Do not rely on host.docker.internal as a general host-service path because it bypasses the OpenShell policy path and may not be reachable. Refer to Agent cannot reach a host-side HTTP service.

Adding a host to the egress policy permits a connection only when the endpoint, port, method, and binary rules match. OpenShell applies SSRF protection separately. It can deny a request when the final address resolves to a loopback, private, link-local, or blocked internal range. If a package installer or browser download still fails after you allow the public host, install the binary at build time. Use nemoclaw onboard --from instead of runtime egress.

Static Changes

Static changes modify the policy source that NemoClaw reads during sandbox creation. Follow Change the Baseline Network Policy to edit the agent policy file, rerun onboarding, and verify the result.

Dynamic Changes

Dynamic changes update the OpenShell policy for a running sandbox. Use Apply Policy Presets for convenient reviewed additions. NemoClaw reads, modifies, writes, and verifies the live OpenShell policy without recording a second desired-policy state.

Use Approve or Deny Network Requests for one-off access. Use Replace the Live Network Policy only when a preset cannot express the complete change.

Policy Presets

Maintained policy presets cover common integrations and package services. Follow Apply Policy Presets to preview, apply, reapply, list, or remove them.

For guided service workflows, refer to Common Integration Policy Examples.

Custom Preset Files

Custom preset files add operator-reviewed endpoint access without changing the baseline. Follow Create Custom Policy Presets to author, validate, apply, and remove a custom preset.

That page also contains the URL-based MCP server recipe formerly located in this guide.

Raw TLS Passthrough

Some endpoints require direct TLS negotiation and fail through inspected L7 proxying. Follow Configure Raw TLS Passthrough for the bounded access: full and tls: skip recipe.

Live Policy Replacement

OpenShell policy set replaces the complete live policy. Follow Replace the Live Network Policy to export the round-trippable base, preserve existing entries, and apply a validated replacement.

Agent Policy Context

Agents need a redacted view of active presets and policy verification state. Follow Explain Network Policy to Agents to print or refresh that context and interpret failure classifications.