You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: .agents/skills/debug-navigator-cluster/SKILL.md
+7-7Lines changed: 7 additions & 7 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -1,17 +1,17 @@
1
1
---
2
2
name: debug-navigator-cluster
3
-
description: Debug why a nemoclaw cluster failed to start or is unhealthy. Use when the user has a failed `nemoclaw cluster admin deploy`, cluster health check failure, or wants to diagnose cluster infrastructure issues. Trigger keywords - debug cluster, cluster failing, cluster not starting, deploy failed, cluster troubleshoot, cluster health, cluster diagnose, why won't my cluster start, health check failed.
3
+
description: Debug why a nemoclaw cluster failed to start or is unhealthy. Use when the user has a failed `nemoclaw gateway start`, cluster health check failure, or wants to diagnose cluster infrastructure issues. Trigger keywords - debug cluster, cluster failing, cluster not starting, deploy failed, cluster troubleshoot, cluster health, cluster diagnose, why won't my cluster start, health check failed, gateway start failed, gateway not starting.
4
4
---
5
5
6
6
# Debug NemoClaw Cluster
7
7
8
-
Diagnose why a nemoclaw cluster failed to start after `nemoclaw cluster admin deploy`.
8
+
Diagnose why a nemoclaw cluster failed to start after `nemoclaw gateway start`.
9
9
10
10
## Overview
11
11
12
-
`nemoclaw cluster admin deploy` creates a Docker container running k3s with the NemoClaw server and Envoy Gateway deployed via Helm. The deployment stages, in order, are:
12
+
`nemoclaw gateway start` creates a Docker container running k3s with the NemoClaw server and Envoy Gateway deployed via Helm. The deployment stages, in order, are:
13
13
14
-
1.**Pre-deploy check**: `nemoclaw cluster admin deploy` in interactive mode prompts to **reuse** (keep volume, clean stale nodes) or **recreate** (destroy everything, fresh start). `mise run cluster` always recreates before deploy.
14
+
1.**Pre-deploy check**: `nemoclaw gateway start` in interactive mode prompts to **reuse** (keep volume, clean stale nodes) or **recreate** (destroy everything, fresh start). `mise run cluster` always recreates before deploy.
15
15
2. Ensure cluster image is available (local build or remote pull)
16
16
3. Create Docker network (`navigator-cluster`) and volume (`navigator-cluster-{name}`)
17
17
4. Create and start a privileged Docker container (`navigator-cluster-{name}`)
@@ -31,7 +31,7 @@ For local deploys, metadata endpoint selection now depends on Docker connectivit
31
31
- default local Docker socket (`unix:///var/run/docker.sock`): `https://127.0.0.1:{port}` (default port 8080)
32
32
- TCP Docker daemon (`DOCKER_HOST=tcp://<host>:<port>`): `https://<host>:{port}` for non-loopback hosts
33
33
34
-
The host port is configurable via `--port` on `nemoclaw cluster admin deploy` (default 8080) and is stored in `ClusterMetadata.gateway_port`.
34
+
The host port is configurable via `--port` on `nemoclaw gateway start` (default 8080) and is stored in `ClusterMetadata.gateway_port`.
35
35
36
36
The TCP host is also added as an extra gateway TLS SAN so mTLS hostname validation succeeds.
37
37
@@ -302,7 +302,7 @@ If DNS is broken, all image pulls from the distribution registry will fail, as w
302
302
| Helm install job failed | Chart values error or dependency issue | Check `helm-install-navigator` job logs in `kube-system`|
303
303
| Architecture mismatch (remote) | Built on arm64, deploying to amd64 | Cross-build the image for the target architecture |
| Port conflict | Another service on 6443 or the configured gateway host port (default 8080) | Stop conflicting service or use `--port` to pick a different host port |
305
+
| Port conflict | Another service on 6443 or the configured gateway host port (default 8080) | Stop conflicting service or use `--port`on `nemoclaw gateway start`to pick a different host port |
306
306
| gRPC connect refused to `127.0.0.1:443` in CI | Docker daemon is remote (`DOCKER_HOST=tcp://...`) but metadata still points to loopback | Verify metadata endpoint host matches `DOCKER_HOST` and includes non-loopback host |
307
307
| DNS failures inside container | Entrypoint DNS detection failed | Check `/etc/rancher/k3s/resolv.conf` and container startup logs |
308
308
|`metrics-server` errors in logs | Normal k3s noise, not the root cause | These errors are benign — look for the actual failing health check component |
Copy file name to clipboardExpand all lines: .agents/skills/nemoclaw-cli/SKILL.md
+58-55Lines changed: 58 additions & 55 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -1,6 +1,6 @@
1
1
---
2
2
name: nemoclaw-cli
3
-
description: Guide agents through using the NemoClaw CLI (nemoclaw) for sandbox management, provider configuration, policy iteration, BYOC workflows, and inference routing. Covers basic through advanced multi-step workflows. Trigger keywords - nemoclaw, sandbox create, sandbox connect, sandbox logs, provider create, policy set, policy get, image push, port forward, BYOC, bring your own container, use nemoclaw, run nemoclaw, CLI usage, manage sandbox, manage provider.
3
+
description: Guide agents through using the NemoClaw CLI (nemoclaw) for sandbox management, provider configuration, policy iteration, BYOC workflows, and inference routing. Covers basic through advanced multi-step workflows. Trigger keywords - nemoclaw, sandbox create, sandbox connect, logs, provider create, policy set, policy get, image push, forward, port forward, BYOC, bring your own container, use nemoclaw, run nemoclaw, CLI usage, manage sandbox, manage provider, gateway start, gateway select.
4
4
---
5
5
6
6
# NemoClaw CLI
@@ -9,7 +9,7 @@ Guide agents through using the `nemoclaw` CLI for sandbox and platform managemen
9
9
10
10
## Overview
11
11
12
-
The NemoClaw CLI (`nemoclaw`) is the primary interface for managing sandboxes, providers, policies, inference routes, and clusters. This skill teaches agents how to orchestrate CLI commands for common and complex workflows.
12
+
The NemoClaw CLI (`nemoclaw`) is the primary interface for managing sandboxes, providers, policies, inference routes, and gateways. This skill teaches agents how to orchestrate CLI commands for common and complex workflows.
13
13
14
14
**Companion skill**: For creating or modifying sandbox policy YAML content (network rules, L7 inspection, access presets), use the `generate-sandbox-policy` skill. This skill covers the CLI *commands* for the policy lifecycle; `generate-sandbox-policy` covers policy *content authoring*.
15
15
@@ -26,7 +26,7 @@ This is your primary fallback. Use it freely -- the CLI's help output is authori
26
26
## Prerequisites
27
27
28
28
-`nemoclaw` is on the PATH (install via `cargo install --path crates/navigator-cli`)
29
-
- Docker is running (required for cluster operations and BYOC)
29
+
- Docker is running (required for gateway operations and BYOC)
30
30
- For remote clusters: SSH access to the target host
31
31
32
32
## Command Reference
@@ -42,21 +42,21 @@ Use this workflow when no cluster exists yet and the user wants to get a sandbox
42
42
### Step 1: Bootstrap a cluster
43
43
44
44
```bash
45
-
nemoclaw cluster admin deploy
45
+
nemoclaw gateway start
46
46
```
47
47
48
-
This provisions a local k3s cluster in Docker. The CLI will prompt interactively if a cluster already exists. The cluster is automatically set as the active cluster.
48
+
This provisions a local k3s cluster in Docker. The CLI will prompt interactively if a cluster already exists. The cluster is automatically set as the active gateway.
Watch for `deny` actions that indicate the user's work is being blocked by policy.
@@ -421,10 +421,10 @@ Watch for `deny` actions that indicate the user's work is being blocked by polic
421
421
422
422
When denied actions are observed:
423
423
424
-
1. Pull current policy: `nemoclaw sandbox policy get work-session --full > policy.yaml`
424
+
1. Pull current policy: `nemoclaw policy get work-session --full > policy.yaml`
425
425
2. Modify the policy to allow the blocked actions (use `generate-sandbox-policy` skill for content)
426
-
3. Push the update: `nemoclaw sandbox policy set work-session --policy policy.yaml --wait`
427
-
4. Verify: `nemoclaw sandbox policy list work-session`
426
+
3. Push the update: `nemoclaw policy set work-session --policy policy.yaml --wait`
427
+
4. Verify: `nemoclaw policy list work-session`
428
428
429
429
The user does not need to disconnect -- policy updates are hot-reloaded within ~30 seconds (or immediately when using `--wait`, which polls for confirmation).
430
430
@@ -472,36 +472,36 @@ nemoclaw cluster inference get
472
472
473
473
---
474
474
475
-
## Workflow 8: Cluster Management
475
+
## Workflow 8: Gateway Management
476
476
477
-
### List and switch clusters
477
+
### List and switch gateways
478
478
479
479
```bash
480
-
nemoclaw cluster list# See all clusters
481
-
nemoclaw cluster use my-cluster # Switch active cluster
482
-
nemoclaw cluster status # Verify connectivity
480
+
nemoclaw gateway select# See all gateways (no args shows list)
481
+
nemoclaw gateway selectmy-cluster# Switch active gateway
482
+
nemoclaw status# Verify connectivity
483
483
```
484
484
485
485
### Lifecycle
486
486
487
487
```bash
488
-
nemoclaw cluster admin deploy# Start local cluster
0 commit comments