Sandbox CLI
기준일: 2026-07-26
공식 기준: Sandbox CLI
Sandbox CLI 문서는 OpenClaw 공식 문서(cli/sandbox)를 한국어로 정리한 가이드입니다. Manage sandbox runtimes and inspect effective sandbox policy 명령·설정 키·코드 예시는 공식 문서를 그대로 보존하며, 해석과 절차 안내는 한국어로 제공합니다. 최종 동작은 설치된 CLI 버전과 공식 원문을 확인하세요.
핵심 요약
Manage sandbox runtimes and inspect effective sandbox policy
한국어 가이드 범위: cli/sandbox 경로의 설정·명령·제약·예시를 학습용으로 재구성합니다.
문서 구성
공식 문서의 주요 섹션은 다음과 같습니다.
- 명령
- Why recreate is needed
- Common triggers
- Registry migration
- 구성
- 관련 문서
상세 내용
본문
Manage sandbox runtimes for isolated agent execution: Docker containers, SSH targets, or OpenShell backends.
위 내용은 공식 문서의 해당 섹션 요지입니다. 세부 플래그·기본값은 원문과
--help를 확인하세요.
명령
이 섹션의 세부 항목은 공식 문서 명령를 참고하세요.
openclaw sandbox list
List sandbox runtimes with status, backend, config match, age, idle time, and associated session/agent.
위 내용은 공식 문서의 해당 섹션 요지입니다. 세부 플래그·기본값은 원문과
--help를 확인하세요.
openclaw sandbox list
openclaw sandbox list --browser # browser containers only
openclaw sandbox list --json
openclaw sandbox recreate
Remove sandbox runtimes to force recreation with current config. Runtimes are recreated automatically the next time the agent is used.
위 내용은 공식 문서의 해당 섹션 요지입니다. 세부 플래그·기본값은 원문과
--help를 확인하세요.
주요 항목:
--all: recreate all sandbox containers--session <key>: recreate the runtime with this exact scope key (as shown bysandbox list); no short-name expansion--agent <id>: recreate runtimes for one agent (matchesagent:<id>andagent:<id>:*)--browser: only affect browser containers--force: skip the confirmation prompt
openclaw sandbox recreate --all
openclaw sandbox recreate --agent mybot # includes agent:mybot:* sub-sessions
openclaw sandbox recreate --session "agent:main:main"
openclaw sandbox recreate --browser --all # only browser containers
openclaw sandbox recreate --all --force # skip confirmation
openclaw sandbox explain
Inspect the effective sandbox mode/scope/workspace access, sandbox tool policy, and elevated-tool gates (with fix-it config key paths).
위 내용은 공식 문서의 해당 섹션 요지입니다. 세부 플래그·기본값은 원문과
--help를 확인하세요.
openclaw sandbox explain
openclaw sandbox explain --session agent:main:main
openclaw sandbox explain --agent work
openclaw sandbox explain --json
Why recreate is needed
Updating sandbox config does not affect running containers: existing runtimes keep their old settings, and idle runtimes are only pruned after prune.idleHours (default 24h). Regularly used agents can keep stale runtimes alive indefinitely. openclaw sandbox recreate removes the old runtime so the next use rebuilds it from current config.
위 내용은 공식 문서의 해당 섹션 요지입니다. 세부 플래그·기본값은 원문과
--help를 확인하세요.
Common triggers
Runtimes are automatically recreated when the agent is next used.
위 내용은 공식 문서의 해당 섹션 요지입니다. 세부 플래그·기본값은 원문과
--help를 확인하세요.
| Change | Command |
|---|---|
Docker image update (agents.defaults.sandbox.docker.image) |
openclaw sandbox recreate --all |
Sandbox config (agents.defaults.sandbox.*) |
openclaw sandbox recreate --all |
SSH target/auth (agents.defaults.sandbox.ssh.{target,workspaceRoot,identityFile,certificateFile,knownHostsFile,identityData,certificateData,knownHostsData}) |
openclaw sandbox recreate --all |
OpenShell source/policy/mode (plugins.entries.openshell.config.{from,mode,policy}) |
openclaw sandbox recreate --all |
setupCommand |
openclaw sandbox recreate --all (or --agent <id> for one agent) |
Registry migration
Sandbox runtime metadata lives in the shared SQLite state database. Older installs may have legacy registry files that regular reads no longer rewrite:
위 내용은 공식 문서의 해당 섹션 요지입니다. 세부 플래그·기본값은 원문과
--help를 확인하세요.
주요 항목:
~/.openclaw/sandbox/containers.json~/.openclaw/sandbox/browsers.json- one JSON shard per container/browser under
~/.openclaw/sandbox/containers/or~/.openclaw/sandbox/browsers/
구성
Sandbox settings live in ~/.openclaw/openclaw.json under agents.defaults.sandbox (per-agent overrides go in agents.entries.*.sandbox):
위 내용은 공식 문서의 해당 섹션 요지입니다. 세부 플래그·기본값은 원문과
--help를 확인하세요.
{
"agents": {
"defaults": {
"sandbox": {
"mode": "all", // off, non-main, all
"backend": "docker", // docker, ssh, openshell (plugin-provided)
"scope": "agent", // session, agent, shared
"docker": {
"image": "openclaw-sandbox:bookworm-slim",
"containerPrefix": "openclaw-sbx-",
// ... more Docker options
},
"prune": {
"idleHours": 24, // auto-prune after 24h idle
"maxAgeDays": 7, // auto-prune after 7 days
},
},
},
},
}
관련 문서
주요 항목:
- CLI reference
- Sandboxing
- Agent workspace
- Doctor: checks sandbox setup.
실습 체크리스트
- 공식 문서와 로컬 버전을 대조합니다:
https://docs.openclaw.ai/cli/sandbox - 관련 CLI는
openclaw --help및 하위 명령--help로 옵션을 확인합니다. - 설정 변경 시
openclaw config/openclaw doctor로 유효성을 검사합니다. - Gateway·채널·플러그인 변경 후에는 필요 시 Gateway를 재시작합니다.
자주 쓰는 명령·설정 예시
openclaw sandbox list
openclaw sandbox list --browser # browser containers only
openclaw sandbox list --json
openclaw sandbox recreate --all
openclaw sandbox recreate --agent mybot # includes agent:mybot:* sub-sessions
openclaw sandbox recreate --session "agent:main:main"
openclaw sandbox recreate --browser --all # only browser containers
openclaw sandbox recreate --all --force # skip confirmation
openclaw sandbox explain
openclaw sandbox explain --session agent:main:main
openclaw sandbox explain --agent work
openclaw sandbox explain --json
{
"agents": {
"defaults": {
"sandbox": {
"mode": "all", // off, non-main, all
"backend": "docker", // docker, ssh, openshell (plugin-provided)
"scope": "agent", // session, agent, shared
"docker": {
"image": "openclaw-sandbox:bookworm-slim",
"containerPrefix": "openclaw-sbx-",
// ... more Docker options
},
"prune": {
"idleHours": 24, // auto-prune after 24h idle
"maxAgeDays": 7, // auto-prune after 7 days
},
},
},
},
}
관련 링크
- 공식 원문: cli/sandbox
- OpenClaw 문서 홈
이 가이드는 공식 문서를 한국어 학습용으로 재구성한 것입니다. 옵션 기본값·플래그 이름은 설치 버전에 따라 달라질 수 있습니다.