Skip to content
Merged
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
70 changes: 55 additions & 15 deletions docs/network-policy/approve-network-requests.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -14,10 +14,13 @@ skill:
Review network requests that the agent makes to endpoints that are not listed in the sandbox policy.
OpenShell intercepts those requests and presents them in the TUI for operator approval.

<Steps toc={true}>

## Prerequisites

- A running NemoClaw sandbox.
- The OpenShell CLI on your `PATH`.
- Access to the host where the sandbox is running.

## Open the TUI

Expand All @@ -34,7 +37,13 @@ openshell term
<Tab title="Remote Sandbox">

Connect to the remote host first.
Use a host that resolves from your terminal, such as a Brev SSH alias or `user@host`.
Replace `<your-sandbox-host>` with the SSH host or alias where your NemoClaw sandbox is running.
Use a host that resolves from your terminal, such as a Brev SSH alias.

```bash
ssh <your-sandbox-host>
```

Then run the TUI from the NemoClaw directory on that host.

```bash
Expand All @@ -47,6 +56,7 @@ openshell term
</Tabs>

The TUI shows the sandbox state, active inference provider, and live network activity.
From the dashboard, select the running sandbox with `j` or `k`, then press `Enter` to open the sandbox view.

## Trigger a Blocked Request

Expand All @@ -59,27 +69,57 @@ The blocked request includes the following details:

## Approve or Deny the Request

The TUI shows an approval prompt for each blocked request.
Blocked requests appear as pending entries in the sandbox view's `Network Rules` panel.
After the sandbox opens, the TUI focuses the sandbox policy view.
Press `r` to focus `Network Rules`.
Use `j` or `k` to select a pending rule, and press `Enter` to inspect its details.

- Select **Approve** to add the endpoint to the running policy for the current session.
- Select **Deny** to keep the endpoint blocked.
- Press `a` to approve the selected pending rule and add the endpoint to the running policy for the current session.
- Press `x` to reject the selected pending rule and keep the endpoint blocked.
- Press `A` to approve all pending rules, then press `y` or `Enter` at the confirmation prompt.

Approved endpoints remain in the running policy until the sandbox stops.
Approved endpoints remain in the running policy for the sandbox instance.
They reset to the baseline when you destroy and recreate the sandbox.
They are not persisted to the baseline policy file.
To keep an endpoint allowed after restart, update the policy YAML or apply a preset as described in [Customize the Sandbox Network Policy](customize-network-policy).

## Run the Walkthrough

From the NemoClaw repository root, run the walkthrough script after you onboard at least one sandbox and confirm that it is reachable:

```bash
./scripts/walkthrough.sh
```
To keep an endpoint allowed for future sandbox instances, update the policy YAML or apply a preset as described in [Customize the Sandbox Network Policy](customize-network-policy).
Rejected rules stay blocked unless you later approve the same rule or add a matching endpoint to the policy.

## Run the Walkthrough Script

The walkthrough script is available in the NemoClaw repository at [`scripts/walkthrough.sh`](https://github.com/NVIDIA/NemoClaw/blob/main/scripts/walkthrough.sh).
It requires a cloned NemoClaw source checkout on the host where the sandbox is running.

<Steps>
<Step>
If the sandbox runs on a remote host, SSH to that host before you clone the repository and run the script.
</Step>
<Step>
Clone the NemoClaw repository on the host where the sandbox is running.
Do this even if you installed NemoClaw with the public installer, because the walkthrough script is a source-checkout helper.

```bash
git clone https://github.com/NVIDIA/NemoClaw.git ~/nemoclaw
cd ~/nemoclaw
```
</Step>
<Step>
Onboard at least one sandbox and confirm that it is attached to the active gateway.
</Step>
<Step>
Run the walkthrough script from the NemoClaw repository root.

```bash
./scripts/walkthrough.sh
```
Comment on lines +106 to +113

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🎯 Functional Correctness | 🟠 Major | ⚡ Quick win

Document the required sandbox alias, or this walkthrough is not literal.

The linked scripts/walkthrough.sh connects with openshell sandbox connect nemoclaw, so “at least one onboarded sandbox” is not enough to follow these steps verbatim.
Please either tell readers to onboard a sandbox named nemoclaw or call out that they must edit the script for a different alias.

Also applies to: 117-119

🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@docs/network-policy/approve-network-requests.mdx` around lines 106 - 113, The
walkthrough text is too vague because scripts/walkthrough.sh expects the sandbox
alias nemoclaw, so update the instructions in approve-network-requests.mdx to
either explicitly tell readers to onboard a sandbox named nemoclaw or clearly
state they must edit the script for a different alias. Make sure the affected
Step content around the onboarding guidance and walkthrough command matches what
the script actually does.

</Step>
</Steps>

The script opens a split tmux session with the TUI on the left and the agent on the right.
The walkthrough requires tmux and the `NVIDIA_INFERENCE_API_KEY` environment variable.
The walkthrough requires `tmux`, the `NVIDIA_INFERENCE_API_KEY` environment variable, and at least one onboarded sandbox attached to the active gateway.
It attaches to an existing sandbox.

</Steps>

## Related Topics

- [Customize the Sandbox Network Policy](customize-network-policy) to add endpoints permanently.
Expand Down
Loading