/** * NemoClaw Adapter * * Integrates NVIDIA NemoClaw sandboxed agent execution with the * SwarmOrchestrator. NemoClaw runs agents inside OpenShell sandboxes * with deny-by-default network policies and Landlock filesystem isolation. * * This adapter manages: * - Sandbox lifecycle (create, status, connect, destroy) * - Network policy generation and application * - Blueprint execution (plan, apply, status, rollback) * - Command execution inside sandboxes * * BYOC (Bring Your Own Client): No runtime dependency on openshell CLI * or NemoClaw. Provide an executor via config, or let the adapter shell * out to `openshell` if available on PATH. * * Usage — default (CLI on PATH): * const adapter = new NemoClawAdapter(); * await adapter.initialize({ options: { sandboxImage: 'ghcr.io/nvidia/...' } }); * adapter.registerSandboxAgent('worker-1', { sandboxName: 'my-sandbox' }); * * Usage — custom executor (bring-your-own): * adapter.registerSandboxAgent('worker-1', { * sandboxName: 'my-sandbox', * executor: async (cmd, args) => myOpenShellWrapper(cmd, args), * }); * * @module NemoClawAdapter * @version 1.0.0 */ import { BaseAdapter } from './base-adapter'; import type { AdapterConfig, AdapterCapabilities, AgentPayload, AgentContext, AgentResult } from '../types/agent-adapter'; /** Blueprint execution action */ export type BlueprintAction = 'plan' | 'apply' | 'status' | 'rollback'; /** Sandbox state as reported by openshell */ export type SandboxState = 'running' | 'stopped' | 'creating' | 'error' | 'unknown'; /** * User-supplied executor for openshell CLI commands. * Receives the subcommand and arguments, returns stdout string. * Throw on non-zero exit. */ export type OpenShellExecutor = (subcommand: string, args: string[], options?: { timeout?: number; env?: Record; }) => Promise; /** Network policy endpoint definition */ export interface PolicyEndpoint { /** Hostname to allow (e.g. "api.nvidia.com") */ host: string; /** Port number (default: 443) */ port?: number; /** Protocol — "rest" or "grpc" */ protocol?: 'rest' | 'grpc'; /** Enforcement mode */ enforcement?: 'enforce' | 'log'; /** TLS handling */ tls?: 'terminate' | 'passthrough'; /** HTTP method/path rules */ rules?: Array<{ allow: { method: string; path: string; }; }>; } /** Named network policy group */ export interface NetworkPolicy { /** Policy group name (e.g. "nvidia", "mcp_server") */ name: string; /** Allowed endpoints */ endpoints: PolicyEndpoint[]; /** Binaries allowed to use this policy */ binaries?: string[]; } /** Blueprint run result */ export interface BlueprintRunResult { success: boolean; runId: string; action: BlueprintAction; output: string; exitCode: number; } /** Sandbox status information */ export interface SandboxStatus { name: string; state: SandboxState; uptime?: number; image?: string; policies?: string[]; } /** Configuration for a registered NemoClaw agent */ export interface NemoClawAgentConfig { /** Sandbox name this agent runs in */ sandboxName: string; /** Container image for sandbox creation (used if sandbox doesn't exist) */ sandboxImage?: string; /** Network policies to apply to this agent's sandbox */ policies?: NetworkPolicy[]; /** Blueprint path for plan/apply operations */ blueprintPath?: string; /** Blueprint profile name */ profile?: string; /** Custom executor — overrides the adapter-level executor */ executor?: OpenShellExecutor; /** Command to run inside the sandbox for agent execution */ command?: string; /** Ports to forward from the sandbox */ forwardPorts?: number[]; /** Environment variables to set inside the sandbox */ env?: Record; } /** * Adapter that connects NVIDIA NemoClaw sandboxed agents to the * SwarmOrchestrator. Manages sandbox lifecycle, network policies, * and blueprint execution with deny-by-default security. */ export declare class NemoClawAdapter extends BaseAdapter { readonly name = "nemoclaw"; readonly version = "1.0.0"; private agents; private executor; private defaultImage; get capabilities(): AdapterCapabilities; initialize(config: AdapterConfig): Promise; shutdown(): Promise; /** * Register an agent that runs inside a NemoClaw sandbox. * * @param agentId Unique identifier used in `delegateTask` calls. * @param config Sandbox agent configuration. */ registerSandboxAgent(agentId: string, config: NemoClawAgentConfig): void; /** * Create a sandbox if it doesn't already exist. * Returns the sandbox status after creation. */ createSandbox(sandboxName: string, image?: string, forwardPorts?: number[]): Promise; /** * Get the current status of a sandbox. */ getSandboxStatus(sandboxName: string): Promise; /** * Destroy a sandbox. Use with caution — this is irreversible. */ destroySandbox(sandboxName: string): Promise; /** * Execute a command inside a sandbox and return the output. */ execInSandbox(sandboxName: string, command: string, env?: Record): Promise; /** * Apply network policies to a sandbox. * Generates YAML and applies via `openshell policy set`. */ applyPolicies(policies: NetworkPolicy[]): Promise; /** * Generate a Network-AI MCP server policy preset. * This allows the sandbox to connect back to the host's MCP server. * * @param host Host address for the MCP server (default: "host.docker.internal") * @param port Port number for the MCP server (default: 3001) */ static mcpServerPolicy(host?: string, port?: number): NetworkPolicy; /** * Generate an NVIDIA NIM API policy preset. */ static nvidiaPolicy(): NetworkPolicy; /** * Execute a blueprint action (plan, apply, status, rollback). */ execBlueprint(blueprintPath: string, action: BlueprintAction, options?: { profile?: string; planPath?: string; dryRun?: boolean; }): Promise; executeAgent(agentId: string, payload: AgentPayload, context: AgentContext): Promise; /** * Get the executor function — agent-level override > adapter-level > default CLI. */ private getExecutor; } //# sourceMappingURL=nemoclaw-adapter.d.ts.map