NemoClaw: OpenClaw in a Sandbox on GX10
An agent with tools should sit in a cage that you control. NemoClaw is an open-source NVIDIA reference stack that runs agents such as OpenClaw in isolated environments (sandboxes) of OpenShell — with network policy, keys kept outside the sandbox and managed access to the model. Here we see how it fits together and run it on a server of the NVIDIA GB10 class.
01What you will learn
- What NemoClaw is and how it differs from OpenClaw and from OpenShell.
- Why an agent is run in a sandbox and what the sandbox does.
- What the stack requires and where the documented ground ends for GB10-class machines.
- How to install, configure and verify it, and how to reach the dashboard remotely.
- What NemoClaw does not promise and how to use it sensibly.
02Before you start
- You have done the OpenClaw on GX10 lesson: you know what a Gateway, a tool and an action approval are. Here the same agent goes into an isolated environment.
- A machine of the NVIDIA GB10 class with DGX OS and terminal access (directly or over SSH). How it is prepared is in the n8n on GX10 lesson.
- Internet — the installer and the sandbox image are downloaded from the network.
- A chosen model: local 🔒 local or a cloud provider 🌐 global. For a provider key, prepare it in your environment before the install — never type it into a chat or a page.
| Resource | Minimum | Recommended |
|---|---|---|
| CPU | 4 vCPU | 4+ vCPU |
| Memory | 8 GB | 16 GB |
| Disk | 20 GB free | 40 GB free |
Source: the prerequisites in the NemoClaw documentation, 03.10.2026. The sandbox image is about 2.4 GB compressed. With less than 8 GB of memory the documentation warns of an out-of-memory kill and recommends at least 8 GB of swap. Software: Node.js 22.19+, npm 10+, Python 3 and a container runtime (Docker by default). The installer can install Docker itself and add you to the docker group.
docker group control the daemon with root-level impact. Give this access only to trusted local accounts.03Steps
-
How the stack fits together
Three separate projects, each with its own scope (from the "Ecosystem" page of the NemoClaw documentation):
Project What it is OpenClaw The assistant: runtime, tools, memory, behaviour — inside the container OpenShell The execution environment: sandbox lifecycle, network, filesystem and process policy, routing of model requests NemoClaw The command line and the blueprint above them: onboarding, lifecycle management, status, snapshots, recovery In short: NemoClaw orchestrates OpenShell, and OpenShell isolates and runs OpenClaw. Requests to the model go through the internal address
inference.local, and the provider keys stay outside the sandbox — OpenShell holds them. Network egress is limited by policy; a new connection is allowed or denied by an operator.💡A sandbox is not a guaranteeNVIDIA describes NemoClaw as a reference stack that runs agents "more safely", not as complete protection. The project is at an early (alpha) stage and support is "best effort". Keep the same rules as in the OpenClaw lesson: only known people, approval of every action with a real effect, nothing valuable on a first run. -
Check the machine
bash · on the machineuname -m docker --version node --version free -h df -h ~You expect
aarch64, and memory and disk matching the table. If Docker is missing, the installer will offer to install it; if you prefer to install it yourself, do it first by Docker's documentation. -
Install NemoClaw
The official installer is downloaded from NVIDIA's site. As with any script run through
| bash, it is wise to download and read it first; the documentation gives this way of running it and a variant for automation.bash · on the machinecurl -fsSL https://www.nvidia.com/nemoclaw.sh | bashAccept the third-party software notice when it asks. On DGX Spark, on a qualifying DGX Station and on WSL the installer can show the question
Run express install with these settings? [Y/n]— answering with Enter means the recommended settings for the platform and finishing without more questions. Answeringnleads to a manual choice of agent, provider, model and sandbox name. If you want to pin a version, the documentation shows the variableNEMOCLAW_INSTALL_TAG(on thebashside, not in front ofcurl). -
The onboarding wizard
The wizard runs preflight checks, starts (or reuses) the OpenShell gateway, and asks for the agent, the model provider and the sandbox name. For a first run the documentation advises:
- choose OpenClaw as the agent (it is the default);
- choose a provider as you wish: NVIDIA Endpoints, OpenRouter, OpenAI, Anthropic, Google Gemini, a compatible endpoint, local Ollama or a managed model. Cloud ones are 🌐 global; local ones are 🔒 local. On DGX Spark, if you set no provider in a non-interactive run, local vLLM is chosen automatically;
- accept the suggested name
my-assistant; - skip web search and messaging channels if you wish (you can add them later by running onboarding again and accepting sandbox recreation);
- accept the suggested network policy.
If onboarding is interrupted, continue or start over:
bashnemoclaw onboard --resume # continues an interrupted onboarding nemoclaw onboard --fresh # starts over -
Check that the sandbox is ready
After the readiness summary, check its state. Onboarding itself verifies the sandbox gateway, the dashboard port forward and the
inference.localroute; an unreachable route or an HTTP 5xx response counts as a failed check — the sandbox is not ready and onboarding exits with an error.bashnemoclaw my-assistant status -
A first prompt
The first command prints the dashboard address; open it in a browser. The second command starts OpenClaw's text interface in the terminal. You can also enter a shell inside the sandbox and start it yourself.
bashnemoclaw my-assistant dashboard-url --quiet nemoclaw launch my-assistantor:
bashnemoclaw my-assistant connect openclaw tuiThe first prompt is harmless: "Tell me which tools you have." After that — a read-only task. Do not give the agent anything that must not be lost.
-
Dashboard access from another computer
The dashboard address is on the machine itself (
127.0.0.1) and the port is chosen during onboarding. From another computer you reach it through an SSH tunnel, not by opening a port to the network. The documentation for assisted installs says explicitly: for a remote dashboard use private forwarding over SSH and treat addresses with embedded access as secrets.bash · on your computerssh -L <port>:127.0.0.1:<port> <user>@<server-address>Replace
<port>with the port in the dashboard address. ⚠️ We have not run this tunnel with NemoClaw. The documentation also has a "Deploy to a Headless Server" page. -
Network policy — who can reach what
By default the sandbox has a baseline network policy. When the agent asks for a connection outside it, an operator approves or denies it; the policy can be changed statically or dynamically, and there are ready-made presets. Rule: open only what you need, one connection at a time. The full procedure is in NVIDIA's "Network Policies" and "Customize Network Policy" pages — we do not repeat it here so that it does not go stale.
✅Two things you do not do directlyThe documentation advises: in NemoClaw-managed environments do not runopenshell self-update,npm update -g openshelloropenshell sandbox create. Usenemoclaw onboard; if you change OpenShell by hand, runnemoclaw onboardagain afterwards. -
Upkeep in brief
The installer treats already registered sandboxes as an update and recovery case and does not create a new one; before it replaces the gateway it requires a fresh backup of every registered sandbox. The pages "Update Sandboxes", "Recover and Rebuild Sandboxes" and "Uninstall NemoClaw" describe each case in detail. We have not run them.
04Check
- You know which is OpenClaw, which is OpenShell and which is NemoClaw.
- The machine has at least 8 GB of memory (16 is better) and 20 GB (40 is better) of free disk; Docker works.
nemoclaw my-assistant statusshows a ready sandbox; theinference.localcheck passed.- The dashboard opens locally or through an SSH tunnel; its address was not sent to anyone.
- The first task was read-only; new network connections were approved one at a time.
- The provider key was not written into a chat, a page or a file inside the sandbox.
Test
1. What is NemoClaw?
2. Where are the model provider keys in this stack?
3. What stage is the NemoClaw project at according to its repository?
4. How do you reach the dashboard of a remote machine?
05What's next
06Sources
- NVIDIA NemoClaw on GitHub 🌐 global — description, supported agents, Apache-2.0, alpha.
- NemoClaw: overview · ecosystem — how OpenClaw, OpenShell and NemoClaw fit together.
- NemoClaw: prerequisites — hardware, software, platform table (DGX OS Spark — tested).
- NemoClaw: quickstart with OpenClaw — installer, wizard,
status,launch,connect. - NemoClaw: security best practices · NVIDIA Spark: NemoClaw playbook — NVIDIA's validated path for DGX Spark.
- OpenClaw: OpenShell as a sandbox backend — the other way: the Gateway on the machine, the tools in OpenShell.