diff --git a/docs/network-policy/approve-network-requests.mdx b/docs/network-policy/approve-network-requests.mdx index a343f166ebc..636d2212bab 100644 --- a/docs/network-policy/approve-network-requests.mdx +++ b/docs/network-policy/approve-network-requests.mdx @@ -14,10 +14,13 @@ skill: Review network requests that the agent makes to endpoints that are not listed in the sandbox policy. OpenShell intercepts those requests and presents them in the TUI for operator approval. + + ## Prerequisites - A running NemoClaw sandbox. - The OpenShell CLI on your `PATH`. +- Access to the host where the sandbox is running. ## Open the TUI @@ -34,7 +37,13 @@ openshell term Connect to the remote host first. -Use a host that resolves from your terminal, such as a Brev SSH alias or `user@host`. +Replace `` with the SSH host or alias where your NemoClaw sandbox is running. +Use a host that resolves from your terminal, such as a Brev SSH alias. + +```bash +ssh +``` + Then run the TUI from the NemoClaw directory on that host. ```bash @@ -47,6 +56,7 @@ openshell term The TUI shows the sandbox state, active inference provider, and live network activity. +From the dashboard, select the running sandbox with `j` or `k`, then press `Enter` to open the sandbox view. ## Trigger a Blocked Request @@ -59,27 +69,57 @@ The blocked request includes the following details: ## Approve or Deny the Request -The TUI shows an approval prompt for each blocked request. +Blocked requests appear as pending entries in the sandbox view's `Network Rules` panel. +After the sandbox opens, the TUI focuses the sandbox policy view. +Press `r` to focus `Network Rules`. +Use `j` or `k` to select a pending rule, and press `Enter` to inspect its details. -- Select **Approve** to add the endpoint to the running policy for the current session. -- Select **Deny** to keep the endpoint blocked. +- Press `a` to approve the selected pending rule and add the endpoint to the running policy for the current session. +- Press `x` to reject the selected pending rule and keep the endpoint blocked. +- Press `A` to approve all pending rules, then press `y` or `Enter` at the confirmation prompt. -Approved endpoints remain in the running policy until the sandbox stops. +Approved endpoints remain in the running policy for the sandbox instance. +They reset to the baseline when you destroy and recreate the sandbox. They are not persisted to the baseline policy file. -To keep an endpoint allowed after restart, update the policy YAML or apply a preset as described in [Customize the Sandbox Network Policy](customize-network-policy). - -## Run the Walkthrough - -From the NemoClaw repository root, run the walkthrough script after you onboard at least one sandbox and confirm that it is reachable: - -```bash -./scripts/walkthrough.sh -``` +To keep an endpoint allowed for future sandbox instances, update the policy YAML or apply a preset as described in [Customize the Sandbox Network Policy](customize-network-policy). +Rejected rules stay blocked unless you later approve the same rule or add a matching endpoint to the policy. + +## Run the Walkthrough Script + +The walkthrough script is available in the NemoClaw repository at [`scripts/walkthrough.sh`](https://github.com/NVIDIA/NemoClaw/blob/main/scripts/walkthrough.sh). +It requires a cloned NemoClaw source checkout on the host where the sandbox is running. + + + + If the sandbox runs on a remote host, SSH to that host before you clone the repository and run the script. + + + Clone the NemoClaw repository on the host where the sandbox is running. + Do this even if you installed NemoClaw with the public installer, because the walkthrough script is a source-checkout helper. + + ```bash + git clone https://github.com/NVIDIA/NemoClaw.git ~/nemoclaw + cd ~/nemoclaw + ``` + + + Onboard at least one sandbox and confirm that it is attached to the active gateway. + + + Run the walkthrough script from the NemoClaw repository root. + + ```bash + ./scripts/walkthrough.sh + ``` + + The script opens a split tmux session with the TUI on the left and the agent on the right. -The walkthrough requires tmux and the `NVIDIA_INFERENCE_API_KEY` environment variable. +The walkthrough requires `tmux`, the `NVIDIA_INFERENCE_API_KEY` environment variable, and at least one onboarded sandbox attached to the active gateway. It attaches to an existing sandbox. + + ## Related Topics - [Customize the Sandbox Network Policy](customize-network-policy) to add endpoints permanently.