Skip to main content

deploy-sandbox

Deploys an already-built NAT agent as a policy-governed OpenShell sandbox on a local NeMo Platform, so the same agent image gets Landlock filesystem isolation and a pure default-deny network policy (the sandbox reaches nothing on the network directly; its model calls are brokered by the OpenShell gateway through the inference.local route) for free. Covers the proven wire-inference.local -> package -> DeploymentConfig -> deploy (executor openshell-local) -> wait -> query -> zero-egress proof -> cleanup flow. Use when the user asks to deploy an agent as a sandbox, sandbox a deployment, run an agent under a Landlock/egress policy, or use the openshell-local executor. Trigger keywords - deploy sandbox, sandboxed agent, openshell deployment, openshell-local executor, sandbox policy, egress policy, landlock, governed deployment, network egress governance, inference.local.

Ir para a instalação

Informações da origem

Repositório
NVIDIA-NeMo/nemo-platform
Última atividade na origem
14 de agosto de 2026 às 17:32
Idioma detectado do SKILL.md
inglês
Estrelas
67
Forks
19

Opções de instalação

Por padrão, está selecionado o prompt que primeiro revisa a origem. Você pode mudar para um comando direto ou baixar uma cópia local.

Revise os arquivos de origem

Leia o SKILL.md e os arquivos complementares exibidos pelo SkillsMP antes de decidir se vai instalar.