The KAGAMI mark КАГАМИ
kagami.bg/academy · lesson · machine-readable viewUPDATED 2026-10-03
IDENTITY
module
GX10-04-32 · NemoClaw: OpenClaw in a sandbox on GX10
series
GX10 (local AI server class: NVIDIA GB10, e.g. ASUS Ascent GX10 / DGX Spark)
level
Intermediate
duration
about 1.5 h
prerequisites
Lesson 04-31 (OpenClaw on GX10); a GB10-class machine with DGX OS, terminal access, internet; Docker (the installer can install it); 8 GB RAM minimum (16 recommended) and 20 GB free disk minimum (40 recommended); Node.js 22.19+ and npm 10+
trust_label
UPDATED 2026-10-03 (against the NVIDIA NemoClaw repository and documentation). NOT TESTED: the installer was not run on a GB10 machine. NemoClaw is an alpha project
versions
Hosted installer follows the last-known-good release; repository package version 0.1.0 (2026-10-03). Apache-2.0
language
human view: bg · english edition: /en/academy/gx10/ (same file name)
previous / next
04-31_OpenClaw_Agent.html / GX10 series index
PURPOSE

Understand NVIDIA NemoClaw, an open-source reference stack that runs agents such as OpenClaw inside NVIDIA OpenShell sandboxes, check its requirements, install it with the hosted installer, complete onboarding, verify the sandbox and reach the dashboard remotely through an SSH tunnel.

KEY CONCEPTS
COMMANDS / PATHS
CHECKLIST
NEXT MODULE

Series index: kagami.bg/academy/gx10/ · previous: 04-31 OpenClaw on GX10 · related series: kagami.bg/academy/openclaw/ (security lesson) · offer: Quick experiment (kagami.bg/stalbata/)

SOURCES
TAGS
gx10nvidia-gb10arm64nemoclawopenshellopenclawsandboxai-agentalpha
UPDATED · 03.10.2026

NemoClaw: OpenClaw in a Sandbox on GX10

An agent with tools should sit in a cage that you control. NemoClaw is an open-source NVIDIA reference stack that runs agents such as OpenClaw in isolated environments (sandboxes) of OpenShell — with network policy, keys kept outside the sandbox and managed access to the model. Here we see how it fits together and run it on a server of the NVIDIA GB10 class.

⏱ ~1.5 h Intermediate GX10 NVIDIA GB10 · Docker · OpenShell early (alpha) project
NemoClaw · OpenShell (the sandbox)🔒 local Docker🔒 local Model: local (vLLM or Ollama)🔒 local Model: cloud provider (optional)🌐 global
🔄
UPDATED · 03.10.2026 — what changed
The lesson was written anew. The old version described "NemoClaw" as voice control of a robotic arm: speech recognition, a vision model and an agent, with a promised "~800 ms" latency and model sizes. That is not NemoClaw. According to the official repository and NVIDIA's documentation NemoClaw is a reference stack for running agents (OpenClaw, Hermes, LangChain Deep Agents Code) in OpenShell sandboxes, under the Apache-2.0 licence. So we removed the voice pipeline, the code and the latency and memory numbers. We added: how the stack fits together (OpenClaw · OpenShell · NemoClaw), hardware and software requirements, the installer and wizard, verification, dashboard access and the rules for upkeep. Voice in OpenClaw is covered in a separate lesson. The repository is open source but an early (alpha) project — commands and behaviour may change.
⚠️
What we have not run ourselves
We had no GB10-class machine and we have not run the installer. Everything below follows NVIDIA's official pages as of 03.10.2026, which is why there is no "TESTED" label. NVIDIA lists "DGX OS (Spark) with Docker" as a tested platform; the ASUS Ascent GX10 is not named in their table, only the general GB10 class — ⚠️ check on your own machine. We have also not checked how long the setup takes, nor how a particular model behaves.

01What you will learn

02Before you start

ResourceMinimumRecommended
CPU4 vCPU4+ vCPU
Memory8 GB16 GB
Disk20 GB free40 GB free

Source: the prerequisites in the NemoClaw documentation, 03.10.2026. The sandbox image is about 2.4 GB compressed. With less than 8 GB of memory the documentation warns of an out-of-memory kill and recommends at least 8 GB of swap. Software: Node.js 22.19+, npm 10+, Python 3 and a container runtime (Docker by default). The installer can install Docker itself and add you to the docker group.

⚠️
The docker group is like root
The documentation warns: members of the docker group control the daemon with root-level impact. Give this access only to trusted local accounts.

03Steps

  1. How the stack fits together

    Three separate projects, each with its own scope (from the "Ecosystem" page of the NemoClaw documentation):

    ProjectWhat it is
    OpenClawThe assistant: runtime, tools, memory, behaviour — inside the container
    OpenShellThe execution environment: sandbox lifecycle, network, filesystem and process policy, routing of model requests
    NemoClawThe command line and the blueprint above them: onboarding, lifecycle management, status, snapshots, recovery

    In short: NemoClaw orchestrates OpenShell, and OpenShell isolates and runs OpenClaw. Requests to the model go through the internal address inference.local, and the provider keys stay outside the sandbox — OpenShell holds them. Network egress is limited by policy; a new connection is allowed or denied by an operator.

    💡
    A sandbox is not a guarantee
    NVIDIA describes NemoClaw as a reference stack that runs agents "more safely", not as complete protection. The project is at an early (alpha) stage and support is "best effort". Keep the same rules as in the OpenClaw lesson: only known people, approval of every action with a real effect, nothing valuable on a first run.
  2. Check the machine

    bash · on the machine
    uname -m
    docker --version
    node --version
    free -h
    df -h ~

    You expect aarch64, and memory and disk matching the table. If Docker is missing, the installer will offer to install it; if you prefer to install it yourself, do it first by Docker's documentation.

  3. Install NemoClaw

    The official installer is downloaded from NVIDIA's site. As with any script run through | bash, it is wise to download and read it first; the documentation gives this way of running it and a variant for automation.

    bash · on the machine
    curl -fsSL https://www.nvidia.com/nemoclaw.sh | bash

    Accept the third-party software notice when it asks. On DGX Spark, on a qualifying DGX Station and on WSL the installer can show the question Run express install with these settings? [Y/n] — answering with Enter means the recommended settings for the platform and finishing without more questions. Answering n leads to a manual choice of agent, provider, model and sandbox name. If you want to pin a version, the documentation shows the variable NEMOCLAW_INSTALL_TAG (on the bash side, not in front of curl).

  4. The onboarding wizard

    The wizard runs preflight checks, starts (or reuses) the OpenShell gateway, and asks for the agent, the model provider and the sandbox name. For a first run the documentation advises:

    • choose OpenClaw as the agent (it is the default);
    • choose a provider as you wish: NVIDIA Endpoints, OpenRouter, OpenAI, Anthropic, Google Gemini, a compatible endpoint, local Ollama or a managed model. Cloud ones are 🌐 global; local ones are 🔒 local. On DGX Spark, if you set no provider in a non-interactive run, local vLLM is chosen automatically;
    • accept the suggested name my-assistant;
    • skip web search and messaging channels if you wish (you can add them later by running onboarding again and accepting sandbox recreation);
    • accept the suggested network policy.

    If onboarding is interrupted, continue or start over:

    bash
    nemoclaw onboard --resume    # continues an interrupted onboarding
    nemoclaw onboard --fresh     # starts over
  5. Check that the sandbox is ready

    After the readiness summary, check its state. Onboarding itself verifies the sandbox gateway, the dashboard port forward and the inference.local route; an unreachable route or an HTTP 5xx response counts as a failed check — the sandbox is not ready and onboarding exits with an error.

    bash
    nemoclaw my-assistant status
  6. A first prompt

    The first command prints the dashboard address; open it in a browser. The second command starts OpenClaw's text interface in the terminal. You can also enter a shell inside the sandbox and start it yourself.

    bash
    nemoclaw my-assistant dashboard-url --quiet
    nemoclaw launch my-assistant

    or:

    bash
    nemoclaw my-assistant connect
    openclaw tui

    The first prompt is harmless: "Tell me which tools you have." After that — a read-only task. Do not give the agent anything that must not be lost.

  7. Dashboard access from another computer

    The dashboard address is on the machine itself (127.0.0.1) and the port is chosen during onboarding. From another computer you reach it through an SSH tunnel, not by opening a port to the network. The documentation for assisted installs says explicitly: for a remote dashboard use private forwarding over SSH and treat addresses with embedded access as secrets.

    bash · on your computer
    ssh -L <port>:127.0.0.1:<port> <user>@<server-address>

    Replace <port> with the port in the dashboard address. ⚠️ We have not run this tunnel with NemoClaw. The documentation also has a "Deploy to a Headless Server" page.

  8. Network policy — who can reach what

    By default the sandbox has a baseline network policy. When the agent asks for a connection outside it, an operator approves or denies it; the policy can be changed statically or dynamically, and there are ready-made presets. Rule: open only what you need, one connection at a time. The full procedure is in NVIDIA's "Network Policies" and "Customize Network Policy" pages — we do not repeat it here so that it does not go stale.

    ✅
    Two things you do not do directly
    The documentation advises: in NemoClaw-managed environments do not run openshell self-update, npm update -g openshell or openshell sandbox create. Use nemoclaw onboard; if you change OpenShell by hand, run nemoclaw onboard again afterwards.
  9. Upkeep in brief

    The installer treats already registered sandboxes as an update and recovery case and does not create a new one; before it replaces the gateway it requires a fresh backup of every registered sandbox. The pages "Update Sandboxes", "Recover and Rebuild Sandboxes" and "Uninstall NemoClaw" describe each case in detail. We have not run them.

04Check

Test

1. What is NemoClaw?

2. Where are the model provider keys in this stack?

3. What stage is the NemoClaw project at according to its repository?

4. How do you reach the dashboard of a remote machine?

05What's next

06Sources

  1. NVIDIA NemoClaw on GitHub 🌐 global — description, supported agents, Apache-2.0, alpha.
  2. NemoClaw: overview · ecosystem — how OpenClaw, OpenShell and NemoClaw fit together.
  3. NemoClaw: prerequisites — hardware, software, platform table (DGX OS Spark — tested).
  4. NemoClaw: quickstart with OpenClaw — installer, wizard, status, launch, connect.
  5. NemoClaw: security best practices · NVIDIA Spark: NemoClaw playbook — NVIDIA's validated path for DGX Spark.
  6. OpenClaw: OpenShell as a sandbox backend — the other way: the Gateway on the machine, the tools in OpenShell.