Skip to main content Accueil Créateurs jezweb claude-skills nemoclaw-setup
nemoclaw-setup Install and configure NVIDIA NemoClaw (sandboxed OpenClaw agent platform) on Linux. Handles cloudflared tunnels, Docker cgroup fixes, OpenShell, sandbox creation, remote access via Cloudflare Tunnel, and known bug workarounds. Use whenever the user mentions installing NemoClaw, setting up OpenClaw, configuring an NVIDIA Spark or DGX for sandboxed agents, or troubleshooting NemoClaw deployment.
Aller à l'installation Skills Marketplace Découvrez et explorez les compétences IA créées par la communauté.
Installer avec Codex ou Claude Copiez ce prompt, collez-le dans Codex, Claude ou un autre assistant, puis laissez-le vérifier la page du skill et l'installer pour vous.
Copier le promptAfficher les détails du prompt Une commande directe contourne le prompt de vérification. Examinez la source avant de l'exécuter.
npx skills add https://github.com/jezweb/claude-skills --skill nemoclaw-setupLa commande reste sur une seule ligne. Faites défiler horizontalement pour la vérifier avant de la copier.
Vous préférez une copie locale ? Téléchargez les fichiers actuellement disponibles dans SkillsMP.
Télécharger Zip Téléchargement... Australian business English for professional writing — warm, direct, EN-AU spelling (colour, organise, centre), no filler words. Use whenever the user is writing for an Australian audience: emails, chat messages, proposals, client communications, blog posts, web copy, or any business writing. Apply to drafting, editing, and tone-checking professional text.
Hit the Cloudflare REST API directly for operations that wrangler and MCP can't handle well. Bulk DNS, custom hostnames, email routing, cache purge, WAF rules, redirect rules, zone settings, Worker routes, D1 cross-database queries, R2 bulk operations, KV bulk read/write, Vectorize queries, Queues, and fleet-wide resource audits. Produces curl commands or scripts. Triggers: 'cloudflare api', 'bulk dns', 'custom hostname', 'email routing', 'cache purge', 'waf rule', 'd1 query', 'r2 bucket', 'kv bulk', 'vectorize query', 'audit resources', 'fleet operation'.
Generate custom favicons from logos, text, or brand colours. Produces favicon.svg, favicon.ico, apple-touch-icon.png, icon-192/512.png, and web manifest. Use whenever the user wants a favicon, mentions replacing a CMS default favicon, converting a logo into a favicon, creating branded initials icons, or troubleshooting favicon not displaying / iOS black square / missing manifest.
Métiers associés SOC
Basé sur la classification professionnelle SOC
name nemoclaw-setup description Install and configure NVIDIA NemoClaw (sandboxed OpenClaw agent platform) on Linux. Handles cloudflared tunnels, Docker cgroup fixes, OpenShell, sandbox creation, remote access via Cloudflare Tunnel, and known bug workarounds. Use whenever the user mentions installing NemoClaw, setting up OpenClaw, configuring an NVIDIA Spark or DGX for sandboxed agents, or troubleshooting NemoClaw deployment. compatibility claude-code-only
NemoClaw Setup
Install NVIDIA NemoClaw — a sandboxed AI agent platform built on OpenClaw with Landlock + seccomp + network namespace isolation. Runs inside Docker via k3s (OpenShell).
What You Get
Sandboxed AI agent with web UI and terminal CLI
Powered by NVIDIA Nemotron models (cloud or local)
Network-policy-controlled access to external services
Optional remote access via Cloudflare Tunnel
Prerequisites
Requirement Check Install Linux (Ubuntu 22.04+) uname -a— Docker docker pssudo apt install docker.ioNode.js 20+ (22 recommended) node --versionnvm install 22NVIDIA GPU (optional but recommended) nvidia-smi— NVIDIA API key — https://build.nvidia.com/settings/api-keys
Workflow
Step 1: Pre-flight Checks
docker ps 2>/dev/null || echo "Docker not running or no access"
node --version
which nemoclaw && nemoclaw --version
which openshell && openshell --version
If nemoclaw is already installed, skip to Step 4.
Step 2: Install NemoClaw curl -fsSL https://nvidia.com/nemoclaw.sh | bash
This installs NemoClaw and OpenClaw via npm globally (to ~/.npm-global/bin/).
If the installer can't find Node.js , install it first:
curl -fsSL https://deb.nodesource.com/setup_22.x | sudo -E bash -
sudo apt install -y nodejs
Step 3: Install OpenShell curl -LsSf https://raw.githubusercontent.com/NVIDIA/OpenShell/main/install.sh | sh
Installs to ~/.local/bin/openshell.
Step 4: Fix Docker Permissions and cgroup Docker group — the user must be in the docker group:
sudo usermod -aG docker $USER
newgrp docker
cgroup v2 fix — required for k3s inside Docker:
grep cgroup2 /proc/filesystems && echo "cgroup v2 detected — fix needed"
sudo $HOME /.npm-global/bin/nemoclaw setup-spark
This adds "default-cgroupns-mode": "host" to /etc/docker/daemon.json and restarts Docker.
Step 5: Run Onboarding PATH=$HOME /.npm-global/bin:$HOME /.local/bin:$PATH nemoclaw onboard
The interactive wizard will:
Check Docker and OpenShell
Start the OpenShell gateway (k3s in Docker)
Ask for a sandbox name — use claw or any name
Configure the NVIDIA API key
Set up inference (Nemotron 3 Super 120B via cloud API)
Launch OpenClaw inside the sandbox
Apply network policy presets — select the ones you need
Common port conflict : If port 8080 is in use, find and kill the process:
Step 6: Verify
PATH=$HOME /.npm-global/bin:$HOME /.local/bin:$PATH nemoclaw claw status
PATH=$HOME /.npm-global/bin:$HOME /.local/bin:$PATH nemoclaw claw connect
Step 7: Set Up Web UI Access The web UI runs inside the sandbox and needs a port forward:
PATH=$HOME /.npm-global/bin:$HOME /.local/bin:$PATH openshell forward start 18789 claw
Then open: http://127.0.0.1:18789/
Known bug (OpenClaw ≤ v2026.3.11) : "device identity required" error. Workaround — append the gateway token to the URL:
ssh -F /tmp/nemoclaw-ssh-config openshell-claw \
"python3 -c \"import json; print(json.load(open('/sandbox/.openclaw/openclaw.json'))['gateway']['auth']['token'])\""
Then visit: http://127.0.0.1:18789/#token=<gateway-token>
Fix : Update to OpenClaw v2026.3.12+ (see Updating section below).
Step 8: Make the Port Forward Persistent Create a health-checked keepalive script:
cat > ~/.local/bin/nemoclaw-keepalive.sh << 'KEEPALIVE'
export PATH="$HOME /.npm-global/bin:$HOME /.local/bin:/usr/local/bin:/usr/bin:/bin"
cleanup () { kill %1 2>/dev/null; exit 0; }
trap cleanup SIGTERM SIGINT
while true ; do
fuser -k 18789/tcp 2>/dev/null; sleep 1
openshell forward start 18789 claw &
FORWARD_PID=$!; sleep 3
while kill -0 $FORWARD_PID 2>/dev/null; do
if ! curl -sf -o /dev/null --connect-timeout 3 http://127.0.0.1:18789/ 2>/dev/null; then
echo "$(date) : Health check failed, restarting..."
kill $FORWARD_PID 2>/dev/null; wait $FORWARD_PID 2>/dev/null; break
fi
sleep 10
done
echo "$(date) : Forward died, restarting in 3s..." ; sleep 3
done
KEEPALIVE
chmod +x ~/.local/bin/nemoclaw-keepalive.sh
Create the systemd service:
sudo tee /etc/systemd/system/nemoclaw-forward.service << 'SERVICE'
[Unit]
Description=NemoClaw Port Forward with Health Check
After=docker.service
Requires=docker.service
[Service]
Type=simple
User=$USER
Group=docker
Environment=PATH=/home/$USER /.npm-global/bin:/home/$USER /.local/bin:/usr/local/bin:/usr/bin:/bin
ExecStart=/home/$USER /.local/bin/nemoclaw-keepalive.sh
Restart=always
RestartSec=5
KillMode=control-group
[Install]
WantedBy=multi-user.target
SERVICE
sudo systemctl daemon-reload
sudo systemctl enable nemoclaw-forward
sudo systemctl start nemoclaw-forward
Step 9: Remote Access via Cloudflare Tunnel (Optional) If you have a Cloudflare Tunnel already running, add NemoClaw to it.
cloudflared tunnel route dns <tunnel-name> nemoclaw.<domain>
Update tunnel config (/etc/cloudflared/config.yml):
- hostname: nemoclaw.<domain>
service: http://localhost:18789
originRequest:
httpHostHeader: "127.0.0.1:18789"
sudo systemctl restart cloudflared
Update sandbox allowed origins — SSH into the sandbox and add your domain:
openshell sandbox ssh-config claw > /tmp/nemoclaw-ssh-config
ssh -F /tmp/nemoclaw-ssh-config openshell-claw 'python3 -c "
import json
with open(\"/sandbox/.openclaw/openclaw.json\") as f:
config = json.load(f)
config[\"gateway\"][\"controlUi\"][\"allowedOrigins\"].append(\"https://nemoclaw.<domain>\")
config[\"gateway\"][\"trustedProxies\"] = [\"127.0.0.1\", \"::1\", \"172.0.0.0/8\", \"10.0.0.0/8\"]
config[\"gateway\"][\"allowRealIpFallback\"] = True
with open(\"/sandbox/.openclaw/openclaw.json\", \"w\") as f:
json.dump(config, f, indent=2)
print(\"Done. Token:\", config[\"gateway\"][\"auth\"][\"token\"])
"'
Protect with Cloudflare Access — add the hostname to your Access application in the Zero Trust dashboard.
Access URL : https://nemoclaw.<domain>/#token=<gateway-token>
Step 10: Install Custom Skills Skills are markdown files in /sandbox/.openclaw/skills/<name>/SKILL.md. SSH into the sandbox to create them:
ssh -F /tmp/nemoclaw-ssh-config openshell-claw
mkdir -p /sandbox/.openclaw/skills/my-skill
cat > /sandbox/.openclaw/skills/my-skill/SKILL.md << 'EOF'
---
name: my-skill
description: What this skill does.
tools: [exec , read , write]
---
Instructions for the agent...
EOF
Verify with: openclaw skills list
Step 11: Configure the Workspace Update the workspace files so the agent knows who you are:
/sandbox/.openclaw/workspace/USER.md — your profile, preferences
/sandbox/.openclaw/workspace/TOOLS.md — available tools and access
/sandbox/.openclaw/workspace/SOUL.md — agent personality and behaviour
Updating OpenClaw The sandbox bundles OpenClaw at install time. To update:
npm install -g openclaw@latest
nemoclaw claw destroy
nemoclaw onboard
Note : Sandbox network policies block npm/PyPI inside the sandbox. Updates must be done by rebuilding.
Troubleshooting Issue Cause Fix Docker is not runningDocker service stopped or user not in docker group sudo systemctl start docker then newgrp dockercgroup v2 detectedDocker not configured for cgroupns=host sudo nemoclaw setup-sparkPort 8080 in use Another service on that port fuser -k 8080/tcpnemoclaw: command not foundNot in PATH PATH=$HOME/.npm-global/bin:$HOME/.local/bin:$PATHdevice identity requiredBug in OpenClaw ≤ v2026.3.11 Append #token=<gateway-token> to URL, or update to v2026.3.12+ gateway token mismatchToken changed after sandbox rebuild Get new token from sandbox config too many failed auth attemptsRate limited from old token attempts Restart gateway: ssh -F /tmp/nemoclaw-ssh-config openshell-claw 'pkill -f "openclaw gateway"; sleep 2; openclaw gateway &' origin not allowedDomain not in allowedOrigins Add to gateway.controlUi.allowedOrigins in sandbox config Port 18789 not responding SSH tunnel died sudo systemctl restart nemoclaw-forward (auto-recovers within 13s)npm 403 Forbidden inside sandbox Network policy blocking TLS Cannot install packages inside sandbox — rebuild instead Tunnel not found on DNS routeWrong Cloudflare account/cert Check cloudflared tunnel list matches your cert Error 502 on Cloudflare Tunnel connections dropped sudo systemctl restart cloudflaredAssets 404 via Cloudflare Browser not authenticated for sub-requests Hard refresh (Ctrl+Shift+R) after Cloudflare Access login
Architecture Docker (openshell-cluster-<name>)
└─ k3s cluster
├─ NVIDIA device plugin
└─ OpenShell sandbox
├─ OpenClaw agent
├─ NemoClaw plugin
├─ Gateway (WebSocket + REST)
└─ Workspace (SOUL.md, USER.md, TOOLS.md, skills/)
Port forward (systemd): localhost:18789 ←SSH tunnel→ sandbox:18789
Cloudflare Tunnel (optional): nemoclaw.domain → localhost:18789
References