Skip to content

[macOS][Sandbox][Policy&Network] Second NEMOCLAW_GATEWAY_PORT instance breaks first sandbox (sandbox has no spec), dashboards share same port #4865

Description

@PrachiShevate-nv

Summary

Attempting to run two NemoClaw sandboxes against two separate OpenShell gateways (8080 and 8081) results in:

  • Only the latest gateway (nemoclaw-8081) being active.
  • Both sandboxes showing the same dashboard URL (18789).
  • The first sandbox (mac-ollama) becoming unreachable, failing with sandbox has no spec when connecting.

This contradicts the multi-instance test specification that expects two independent gateway+dashboard instances and isolated sandboxes.

Environment

  • Host: macOS
  • NemoClaw CLI: v0.0.59
  • OpenShell: 0.0.44 (docker)
  • Sandboxes:
    • mac-ollama – provider: ollama-local, model: qwen2.5:7b
    • port-test – provider: nvidia-prod, model: nvidia/nemotron-3-super-120b-a12b
  • Ports: 8080/18789 free initially; 8081/18790 free for second instance.

Pre-conditions

  • NemoClaw installed; Docker/OpenShell working.
  • No existing onboarded sandboxes (clean state).
  • Ports 8080/18789 and 8081/18790 available.
  • Default OpenShell gateway uses port 8080.

Steps to Reproduce

1. Onboard first sandbox (default gateway 8080):

nemoclaw onboard
# Name sandbox: mac-ollama
# Choose local Ollama etc.

2. Verify sandbox list:

nemoclaw list

Observed:

Sandboxes:
  mac-ollama
    agent: openclaw
    model: qwen2.5:7b
    provider: ollama-local
    CPU sandbox ...
    dashboard: http://127.0.0.1:18789/

3. Onboard second sandbox with custom gateway port 8081:

NEMOCLAW_GATEWAY_PORT=8081 nemoclaw onboard
# Name sandbox: port-test
# Choose NVIDIA Endpoints etc.

4. Verify sandboxes again:

nemoclaw list

Observed:

Sandboxes:
  mac-ollama
    agent: openclaw
    model: qwen2.5:7b
    provider: ollama-local
    ...
    dashboard: http://127.0.0.1:18789/
  port-test *
    agent: openclaw
    model: nvidia/nemotron-3-super-120b-a12b
    provider: nvidia-prod
    ...
    dashboard: http://127.0.0.1:18789/

Note: both sandboxes report the same dashboard URL (18789).

5. Check OpenShell gateway status:

openshell status

Observed:

Server Status
  Gateway: nemoclaw-8081
  Server:  http://127.0.0.1:8081
  Status:  Connected
  Version: 0.0.44

Only nemoclaw-8081 is active; original nemoclaw-8080 is not reported.

6. Connect to second sandbox (works):

nemoclaw port-test connect

7. Connect to first sandbox (fails):

nemoclaw mac-ollama connect

Actual error:

Unable to verify sandbox 'mac-ollama' against the live OpenShell gateway.
Error: × status: Internal, message: "sandbox has no spec", details: [],
metadata: MetadataMap { headers: {"content-type": "application/grpc",
"date": "Fri, 05 Jun 2026 20:07:20 GMT",
"x-request-id": "0461839c-feb1-40ff-9e52-92aa216dfd19"} }
Check `openshell status` and the active gateway, then retry.

Expected Behavior

  • First onboard succeeds on default gateway (8080), with dashboard on 18789.
  • Second onboard with NEMOCLAW_GATEWAY_PORT=8081:
    • Either starts a second, independent gateway with its own dashboard port (e.g. 18790), or
    • Fails fast with a clear message if multiple simultaneous gateways are not supported.
  • nemoclaw list shows both sandboxes with correct, distinct dashboard URLs.
  • nemoclaw <sandbox> connect routes each sandbox to the gateway that owns it; no sandbox becomes orphaned.

Actual Behavior

  • nemoclaw list shows two sandboxes, both pointing to http://127.0.0.1:18789/.
  • openshell status shows only nemoclaw-8081 active.
  • nemoclaw port-test connect succeeds.
  • nemoclaw mac-ollama connect fails with sandbox has no spec because the active gateway (8081) has never seen the mac-ollama spec created on 8080.
  • The first sandbox is effectively unreachable even though nemoclaw list still shows it.

Impact

  • Users following the documented multi-instance test ("use NEMOCLAW_GATEWAY_PORT=8081 for a second instance") end up with their original sandbox orphaned.
  • Confusing mismatch between nemoclaw list (same dashboard URL for both), openshell status (one gateway), and nemoclaw connect (fails with a low-level error instead of a clear explanation).
  • The test expectation "Destroying one instance does not affect the other; no shared network corruption; no silent reuse of same gateway/TLS cert" is not met.

Suggested Fixes / Clarifications

1. Clarify multi-gateway support:

  • If only one gateway at a time is supported:
    • NEMOCLAW_GATEWAY_PORT=8081 nemoclaw onboard should fail with a clear message: "Multiple OpenShell gateways are not supported; stop the existing gateway on 8080 or reconfigure it instead of starting a new one."
    • The multi-instance test case should be removed or updated.
  • If multi-gateway is intended to be supported:
    • Each sandbox must be pinned to the gateway that created it, with connect routing accordingly.
    • Dashboards must have distinct ports reflected correctly in nemoclaw list.

2. Improve error message for orphaned sandbox:

Instead of sandbox has no spec, surface something like: "Sandbox mac-ollama is registered to gateway nemoclaw-8080, which is not currently running. Start that gateway or migrate the sandbox to the active gateway (nemoclaw-8081)."

3. Fix dashboard URLs in nemoclaw list:

Each sandbox's dashboard URL must be bound to its actual gateway instance, not just the last started gateway.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

NV QABugs found by the NVIDIA QA Teamarea: networkingDNS, proxy, TLS, ports, host aliases, or connectivityarea: sandboxOpenShell sandbox lifecycle, runtime, config, or recovery

Type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions