沙盒命令行界面
管理沙箱容器并检查有效的沙箱策略
管理基于 Docker 的沙箱容器以实现隔离的代理执行。
概述
为了安全起见,OpenClaw 可以在隔离的 Docker 容器中运行代理。 ''sandbox'' 命令可帮助您管理这些容器,尤其是在更新或配置更改之后。
命令
#
`openclaw sandbox explain`
检查有效沙箱模式/范围/工作区访问、沙箱工具策略和提升的门(使用修复配置关键路径)。
openclaw sandbox explain openclaw sandbox explain --session agent:main:main openclaw sandbox explain --agent work openclaw sandbox explain --json
#
`openclaw sandbox list`
列出所有沙箱容器及其状态和配置。
openclaw sandbox list openclaw sandbox list --browser # List only browser containers openclaw sandbox list --json # JSON output
输出包括:
- 容器名称和状态(运行/停止)
- Docker 镜像及其是否与配置匹配
- 年龄(自创建以来的时间)
- 空闲时间(自上次使用以来的时间)- 关联会话/代理
#
`openclaw sandbox recreate`
删除沙箱容器以强制使用更新的图像/配置进行重新创建。
openclaw sandbox recreate --all # Recreate all containers openclaw sandbox recreate --session main # Specific session openclaw sandbox recreate --agent mybot # Specific agent openclaw sandbox recreate --browser # Only browser containers openclaw sandbox recreate --all --force # Skip confirmation
选项:
- ''--all'':重新创建所有沙箱容器
- ''--session <key>'': Recreate containers for a specific session
- ''--agent <id>'': Recreate containers for a specific agent
- ''--browser'':仅重新创建浏览器容器
- ''--force'':跳过确认提示
重要提示: 下次使用代理时会自动重新创建容器。
用例
#
更新 Docker 镜像后
docker pull openclaw-sandbox:latest docker tag openclaw-sandbox:latest openclaw-sandbox:bookworm-slim openclaw sandbox recreate --all
#
更改沙箱配置后
openclaw sandbox recreate --all
#
更改 setupCommand 后
openclaw sandbox recreate --all openclaw sandbox recreate --agent family
#
仅适用于特定代理
openclaw sandbox recreate --agent alfred
为什么需要这个?
问题: 当您更新沙箱 Docker 映像或配置时:
- 现有容器继续使用旧设置运行
- 容器仅在 24 小时不活动后才会被修剪
- 经常使用的代理使旧容器无限期运行
''解决方案:'' 使用 ''openclaw sandbox recreate'' 强制删除旧容器。下次需要时,它们将使用当前设置自动重新创建。
提示:与手动 ''docker rm'' 相比,更喜欢 ''docker rm''。它使用
网关的容器命名并避免范围/会话密钥更改时出现不匹配。
配置
沙箱设置位于 ''agents.defaults.sandbox'' 下的 ''agents.defaults.sandbox'' 中(每个代理的覆盖位于 ''agents.list[].sandbox'' 中):
{
"agents": {
"defaults": {
"sandbox": {
"mode": "all", // off, non-main, all
"scope": "agent", // session, agent, shared
"docker": {
"image": "openclaw-sandbox:bookworm-slim",
"containerPrefix": "openclaw-sbx-",
// ... more Docker options
},
"prune": {
"idleHours": 24, // Auto-prune after 24h idle
"maxAgeDays": 7, // Auto-prune after 7 days
},
},
},
},
}