OpenClawSkills
GitHub
CLI 参考 • 5 分钟阅读

沙盒命令行界面

管理沙箱容器并检查有效的沙箱策略

管理基于 Docker 的沙箱容器以实现隔离的代理执行。

Tutorial.step

概述

为了安全起见,OpenClaw 可以在隔离的 Docker 容器中运行代理。 ''sandbox'' 命令可帮助您管理这些容器,尤其是在更新或配置更改之后。

Tutorial.step

命令

#

Tutorial.step

`openclaw sandbox explain`

检查有效沙箱模式/范围/工作区访问、沙箱工具策略和提升的门(使用修复配置关键路径)。

Bash
openclaw sandbox explain
openclaw sandbox explain --session agent:main:main
openclaw sandbox explain --agent work
openclaw sandbox explain --json

#

Tutorial.step

`openclaw sandbox list`

列出所有沙箱容器及其状态和配置。

Bash
openclaw sandbox list
openclaw sandbox list --browser  # List only browser containers
openclaw sandbox list --json     # JSON output

输出包括:

- 容器名称和状态(运行/停止)

- Docker 镜像及其是否与配置匹配

- 年龄(自创建以来的时间)

- 空闲时间(自上次使用以来的时间)- 关联会话/代理

#

Tutorial.step

`openclaw sandbox recreate`

删除沙箱容器以强制使用更新的图像/配置进行重新创建。

Bash
openclaw sandbox recreate --all                # Recreate all containers
openclaw sandbox recreate --session main       # Specific session
openclaw sandbox recreate --agent mybot        # Specific agent
openclaw sandbox recreate --browser            # Only browser containers
openclaw sandbox recreate --all --force        # Skip confirmation

选项:

- ''--all'':重新创建所有沙箱容器

- ''--session <key>'': Recreate containers for a specific session

- ''--agent <id>'': Recreate containers for a specific agent

- ''--browser'':仅重新创建浏览器容器

- ''--force'':跳过确认提示

重要提示: 下次使用代理时会自动重新创建容器。

Tutorial.step

用例

#

Tutorial.step

更新 Docker 镜像后

Bash
docker pull openclaw-sandbox:latest
docker tag openclaw-sandbox:latest openclaw-sandbox:bookworm-slim





openclaw sandbox recreate --all

#

Tutorial.step

更改沙箱配置后

Bash
openclaw sandbox recreate --all

#

Tutorial.step

更改 setupCommand 后

Bash
openclaw sandbox recreate --all

openclaw sandbox recreate --agent family

#

Tutorial.step

仅适用于特定代理

Bash
openclaw sandbox recreate --agent alfred
Tutorial.step

为什么需要这个?

问题: 当您更新沙箱 Docker 映像或配置时:

- 现有容器继续使用旧设置运行

- 容器仅在 24 小时不活动后才会被修剪

- 经常使用的代理使旧容器无限期运行

''解决方案:'' 使用 ''openclaw sandbox recreate'' 强制删除旧容器。下次需要时,它们将使用当前设置自动重新创建。

提示:与手动 ''docker rm'' 相比,更喜欢 ''docker rm''。它使用

网关的容器命名并避免范围/会话密钥更改时出现不匹配。

Tutorial.step

配置

沙箱设置位于 ''agents.defaults.sandbox'' 下的 ''agents.defaults.sandbox'' 中(每个代理的覆盖位于 ''agents.list[].sandbox'' 中):

Jsonc
{
  "agents": {
    "defaults": {
      "sandbox": {
        "mode": "all", // off, non-main, all
        "scope": "agent", // session, agent, shared
        "docker": {
          "image": "openclaw-sandbox:bookworm-slim",
          "containerPrefix": "openclaw-sbx-",
          // ... more Docker options
        },
        "prune": {
          "idleHours": 24, // Auto-prune after 24h idle
          "maxAgeDays": 7, // Auto-prune after 7 days
        },
      },
    },
  },
}
Tutorial.step

另请参阅

- ''沙盒文档''

- ''代理配置''

- ''Doctor Command'' - 检查沙箱设置