Skip to main content

deploy-sandbox

Deploys an already-built NAT agent as a policy-governed OpenShell sandbox on a local NeMo Platform, so the same agent image gets Landlock filesystem isolation and a pure default-deny network policy (the sandbox reaches nothing on the network directly; its model calls are brokered by the OpenShell gateway through the inference.local route) for free. Covers the proven wire-inference.local -> package -> DeploymentConfig -> deploy (executor openshell-local) -> wait -> query -> zero-egress proof -> cleanup flow. Use when the user asks to deploy an agent as a sandbox, sandbox a deployment, run an agent under a Landlock/egress policy, or use the openshell-local executor. Trigger keywords - deploy sandbox, sandboxed agent, openshell deployment, openshell-local executor, sandbox policy, egress policy, landlock, governed deployment, network egress governance, inference.local.

跳到安装

来源信息

仓库
NVIDIA-NeMo/nemo-platform
最近来源活动
2026年8月14日 17:32
检测到的 SKILL.md 语言
英语
星标
67
分支
19

安装方式

默认使用会先检查来源的 Prompt;你也可以切换为直接命令,或下载本地副本。

检查来源文件

决定是否安装前,请先阅读 SKILL.md,以及 SkillsMP 当前展示的配套文件。