サンドボックス
サンドボックスコンテナを管理し、有効なサンドボックスポリシーを確認します。
分離されたエージェント実行のための Docker ベースのサンドボックスコンテナを管理します。
Overview
セキュリティのため、OpenClaw は分離された Docker コンテナでエージェントを実行できます。''sandbox'' コマンドは、更新や設定変更後にこれらのコンテナを管理するのに役立ちます。
コマンド
#
`openclaw sandbox explain`
有効なサンドボックスモード/スコープ/ワークスペースアクセス、サンドボックスツールポリシー、および昇格ゲートを確認します(修正設定キーパス付き)。
openclaw sandbox explain openclaw sandbox explain --session agent:main:main openclaw sandbox explain --agent work openclaw sandbox explain --json
#
`openclaw sandbox list`
すべてのサンドボックスコンテナとそのステータスと設定を一覧表示します。
openclaw sandbox list openclaw sandbox list --browser # List only browser containers openclaw sandbox list --json # JSON output
出力には以下が含まれます:
- コンテナ名とステータス(実行中/停止)
- Docker イメージと設定と一致するかどうか
- 経過時間(作成からの時間)
- アイドル時間(最後の使用からの時間)- 関連するセッション/エージェント
#
`openclaw sandbox recreate`
更新されたイメージ/設定で再作成を強制するためにサンドボックスコンテナを削除します。
openclaw sandbox recreate --all # Recreate all containers openclaw sandbox recreate --session main # Specific session openclaw sandbox recreate --agent mybot # Specific agent openclaw sandbox recreate --browser # Only browser containers openclaw sandbox recreate --all --force # Skip confirmation
オプション:
- ''--all'':すべてのサンドボックスコンテナを再作成
- ''--session <key>'': Recreate containers for a specific session
- ''--agent <id>'': Recreate containers for a specific agent
- ''--browser'':ブラウザコンテナのみを再作成
- ''--force'':確認プロンプトをスキップ
重要な注意: コンテナは次回のエージェント使用時に自動的に再作成されます。
Use Cases
#
Docker イメージを更新した後
docker pull openclaw-sandbox:latest docker tag openclaw-sandbox:latest openclaw-sandbox:bookworm-slim openclaw sandbox recreate --all
#
サンドボックス設定を変更した後
openclaw sandbox recreate --all
#
setupCommand を変更した後
openclaw sandbox recreate --all openclaw sandbox recreate --agent family
#
特定のエージェントのみ
openclaw sandbox recreate --agent alfred
なぜこれが必要なのですか?
問題: サンドボックス Docker イメージまたは設定を更新するとき:
- 既存のコンテナは古い設定で実行し続けます
- コンテナは24時間の非アクティビティ後にのみプルーニングされます
- 頻繁に使用されるエージェントは古いコンテナを無期限に実行し続けます
''解決策:'' ''openclaw sandbox recreate'' を使用して古いコンテナを強制的に削除します。次回必要なとき、現在の設定で自動的に再作成されます。
ヒント:手動の ''docker rm'' よりも ''docker rm'' を優先してください。それは
ゲートウェイのコンテナ命名を使用し、スコープ/セッションキーが変更されたときの不一致を回避します。
Configuration
サンドボックス設定は ''~/.openclaw/openclaw.json'' の ''agents.defaults.sandbox'' の下にあります(エージェントごとのオーバーライドは ''agents.list[].sandbox'' にあります):
{
"agents": {
"defaults": {
"sandbox": {
"mode": "all", // off, non-main, all
"scope": "agent", // session, agent, shared
"docker": {
"image": "openclaw-sandbox:bookworm-slim",
"containerPrefix": "openclaw-sbx-",
// ... more Docker options
},
"prune": {
"idleHours": 24, // Auto-prune after 24h idle
"maxAgeDays": 7, // Auto-prune after 7 days
},
},
},
},
}