NemoClaw
Deploy NemoClaw, an open source CLI orchestrator from NVIDIA that runs the OpenClaw AI agent inside a Docker sandbox and proxies its network access through OpenShell, a companion process.
You can configure and manage the system using a CLI onboarding wizard that selects an inference provider, collects credentials, and starts the sandbox dashboard. This app creates a limited user on the system named nemoclaw and configures system services for automatic sandbox management.
1. Deploy NemoClaw
Follow the deployment instructions from the Get started section to configure the app, deploy it, and verify software installation.
For information on the app-specific configurations, see the Configuration options section.
Software included
Software installed on your Linode when deploying the app.
| Package | Description |
|---|---|
| NemoClaw CLI | A CLI to orchestrate and manage your AI agent sandbox. |
| Docker | A container runtime for isolating agent execution. |
| OpenShell Gateway | A network proxy for secure sandbox communication. |
| Onboarding Script | A script triggered on your first root login to configure your setup. |
Base distribution and plan
- Supported distribution: Ubuntu 24.04 LTS
- Recommended plans: Use at least a Linode 8GB or higher plan to comfortably run the OpenClaw agent and related services.
Configuration options
Configure the required options to deploy your instance. For additional customization, add advanced options.
The table maps the Cloud Manager UI fields to their corresponding API/CLI keys (stackscript_data) required for automated deployments.
StackScript ID: 2164119
| UI field | API/CLI key | Description |
|---|---|---|
| Required options | ||
| Limited sudo user | user_name | Your preferred username for the limited sudo user, entered without any capital letters, spaces, or special characters. When adding a limited sudo user, the user is created with a strong generated password for your new Linode instance, and the account is assigned to the sudo group, which provides elevated permissions when running commands with the sudo prefix.Note: For easier and more secure access with the sudo user, add an account SSH key for the Cloud Manager user during deployment and select that user as an |
| Email address (for the Let's Encrypt SSL certificate) | soa_email_address | The email address you want to use for generating the SSL certificates via Let’s Encrypt. |
| Advanced options | ||
| Disable root access over SSH | disable_root | Applies to a limited sudo user. To block the root user from logging in over SSH, select Yes. Defaults to No. Note: When you disable the root user from logging in over SSH and don't provide a valid Account SSH Key assigned to the |
| Linode API token | token_password | Applies to a custom domain. The Linode API token if you want to use Linode's DNS Manager to manage DNS records for your custom domain. Follow Manage personal access tokens to get your token on your account with Read/Write access to Domains.
|
| Subdomain | subdomain | Applies to a custom domain. The subdomain you want to use, like blog for blog.example.com. Use it only if you specify a Domain. |
| Domain | domain | Applies to a custom domain. The domain name you want to use, like example.com. Use it only if you specify a Linode API token. |
| Optional data exporter Add-ons | add_ons | An option to include add-ons for your deployment. Possible values are:
|
Notes:
- After the app deployment completes, the password for your limited sudo user is generated and stored in the
.credentialsfile in the home directory, along with application-specific passwords. Log in to your instance asrootthrough the Lish console or SSH, then runcat /home/$USERNAME/.credentialsto view its contents.- You can automatically configure a custom domain (optional) during deployment. To do that:
- First, configure your domain to use Linode’s name servers via your registrar. See Configure your domain's authoritative name servers for details.
- Once you complete that, specify the Linode API token, subdomain, and domain for the app in Cloud Manager or via API/CLI/Terraform.
Use API, CLI, or Terraform
In addition to deploying the app to a new Linode instance via Cloud Manager, you can also use the Linode API, CLI, or Terraform. When running the operation, you need to provide the StackScript ID, supported Linux distribution, and app-specific fields along with the standard Linode deployment configurations.
Note: Generate a personal access token to authenticate your API, CLI, or Terraform requests.
curl --location 'https://api.linode.com/v4/linode/instances' \
--header 'Content-Type: application/json' \
--header 'Accept: application/json' \
--header 'Authorization: Bearer abc123def456hij789klm' \
--data-raw '{
"region": "us-east",
"type": "g6-standard-2",
"image": "linode/ubuntu24.04",
"label": "my-nemoclaw-one-click-app",
"root_pass": "@C0mpl3x#P@ssw0rd",
"stackscript_id": 2164119,
"stackscript_data": {
"user_name":"jsmith",
"soa_email_address":"jsmith@example.com"
}
}'linode-cli linodes create \
--region us-east \
--type g6-standard-2 \
--label my-nemoclaw-one-click-app \
--image linode/ubuntu24.04 \
--root_pass @C0mpl3x#P@ssw0rd \
--stackscript_id 2164119 \
--stackscript_data '{"user_name":"jsmith", "soa_email_address":"jsmith@example.com"}'resource "linode_instance" "my-linode" {
region = "us-east"
type = "g6-standard-2"
label = "my-nemoclaw-one-click-app"
image = "linode/ubuntu24.04"
root_pass = "@C0mpl3x#P@ssw0rd"
stackscript_id = 2164119
stackscript_data = {
"user_name" = "jsmith"
"soa_email_address" = "jsmith@example.com"
}
}2. Access NemoClaw
Onboard NemoClaw
Once the deployment is complete, go through the onboarding wizard to configure your inference provider and start the dashboard. This app triggers onboarding for you when you log in as root.
-
Log in to your instance.
If you disabled root login to the server during the setup of the NemoClaw app, log in as a sudo user.
ssh root@YOUR_INSTANCE_IPReplace
YOUR_INSTANCE_IPwith the IP address of your Linode instance. -
Escalate privileges to root. Once you’ve logged in, the motd (message of the day) appears.
********************************************************* Akamai Connected Cloud NemoClaw Quick Deploy App Dashboard Access: SSH tunnel required (see details below) Credentials File: /home/admin/.credentials Documentation: https://techdocs.akamai.com/quick-deploy-apps/docs/nemoclaw ********************************************************* -
Become root by running
sudo su -. When prompted for the sudo password, paste it from the.credentialsfile. -
The onboarding script runs automatically, and you're prompted to start the setup wizard for NemoClaw.
Do you want to run the nemoclaw onboard wizard? [y/n]: -
If you're ready to perform the onboarding, enter
y. It takes you to thenemoclaw onboardwizard where you can complete the configuration. It prompts you to:-
Select an inference provider: Choose from the supported options, including NVIDIA Build/Endpoints, OpenAI, Anthropic, OpenRouter, Gemini, or a self-hosted OpenAI-compatible server.
-
Supply provider credentials: Enter the API key or connection details for your chosen provider.
Important: NemoClaw requires an external Large Language Model (LLM) to function. You must provide valid credentials for at least one of the supported inference providers during onboarding.
Once the setup is complete, the onboarding script is removed, and it won’t prompt again on the next login.
-
Access the dashboard
The NemoClaw dashboard isn't exposed on a public HTTP(S) endpoint. Instead, access it securely through SSH tunneling from your local machine.
-
On your local machine, configure an SSH tunnel.
ssh -L 18789:127.0.0.1:18789 root@YOUR_INSTANCE_IPReplace
YOUR_INSTANCE_IPwith your Linode instance’s IP address. This forwards the port18789on your local machine to the dashboard port on the instance. -
While the tunnel is open, get the dashboard URL and token by running this command on the instance.
sudo -i -u nemoclaw nemoclaw dashboard-urlDashboard URL: http://127.0.0.1:18789/#token=1Ab23cd45eFgh67iJk8lmN9012oP3qR Treat this URL like a password -- do not log, share, or commit it. -
Open your browser and visit the local URL with the token to access the dashboard.
Important: The dashboard token is sensitive. Treat it like a password and don't share or commit it to version control.
Additional resources
For more information about the installed packages, see their official documentation.
- NemoClaw GitHub Repository for the latest updates and community support.
- NemoClaw Documentation for advanced features and configurations.
- Inference Provider Documentation for optimizing your chosen AI model endpoint.
Note that we can't vouch for the accuracy or timeliness of externally hosted resources.
Updated about 11 hours ago
