Architecture Diagrams Reference
Print-friendly reference of all NemoClaw architecture diagrams
1. Component Hierarchy (Outside to Inside)
flowchart TB
subgraph HOST["HOST MACHINE"]
DEV["Developer Terminal
> dcode / > nemoclaw"]
subgraph NEMOCLAW["NemoClaw (Orchestration Layer)"]
CLI["NemoClaw CLI"]
BP["Blueprint Resolver"]
end
subgraph OPENSHELL["OpenShell (Sandbox Layer)"]
GW["Gateway"]
PE["Policy Engine"]
PR["Privacy Router"]
end
end
subgraph SANDBOX["SANDBOX CONTAINER"]
subgraph AGENT["Agent (OpenClaw/dcode)"]
RT["Runtime"]
TOOLS["Tools"]
MEM["Memory"]
end
end
subgraph INFERENCE["MODEL"]
PROV["Nemotron / Claude / GPT"]
end
DEV --> CLI --> GW --> SANDBOX
AGENT -.->|"inference.local"| PR --> PROV
style NEMOCLAW fill:#e8f5e9,stroke:#76b900
style OPENSHELL fill:#e3f2fd,stroke:#1a5fb4
style SANDBOX fill:#fff3e0,stroke:#f57c00
NemoClaw orchestrates → OpenShell sandboxes → Agent executes → Model thinks
2. Five Security Layers (Deny-by-Default)
flowchart LR
N["1. NETWORK
Egress rules
SSRF protection"]
F["2. FILESYSTEM
Landlock LSM
Read-only paths"]
P["3. PROCESS
Capability drops
no-new-privileges"]
G["4. GATEWAY
Device auth
Loopback binding"]
I["5. INFERENCE
Credential isolation
inference.local"]
N --> F --> P --> G --> I
style N fill:#e3f2fd,stroke:#1a5fb4
style F fill:#e8f5e9,stroke:#76b900
style P fill:#fff3e0,stroke:#f57c00
style G fill:#f3e5f5,stroke:#7b1fa2
style I fill:#fce4ec,stroke:#c2185b
Mnemonic: "No Funny Paths Get In" (Network, Filesystem, Process, Gateway, Inference)
3. Inference Routing (Credential Isolation)
sequenceDiagram
participant A as Agent
participant I as inference.local
participant O as OpenShell
participant C as Credential Store
participant M as Model
A->>I: Request (no creds)
I->>O: Intercept
O->>C: Fetch key
C-->>O: API key
O->>M: Forward (creds injected)
M-->>O: Response
O-->>A: Response (creds stripped)
Note over A,M: Agent NEVER sees API keys
Credentials stay on host, injected at egress, stripped before return
4. The Agent Loop
flowchart LR
I["1. INSPECT
Read files"]
E["2. EDIT
Modify code"]
R["3. RUN
Execute commands"]
T["4. TEST
Validate"]
S["5. SUMMARIZE
Report"]
I --> E --> R --> T --> S
S -.->|"If more work"| I
The cycle dcode/OpenClaw follows for each task
5. NemoClaw Blueprint Stack
flowchart TB
L1["LangChain Deep Agents (dcode)
Agent Harness"]
L2["NVIDIA Nemotron 3 Ultra
Open Model"]
L3["NVIDIA OpenShell Runtime
Governed Sandbox"]
L1 --> L2 --> L3
style L1 fill:#fff3e0,stroke:#f57c00
style L2 fill:#f3e5f5,stroke:#7b1fa2
style L3 fill:#e3f2fd,stroke:#1a5fb4
"Agent performance improves when model, harness, evals, and runtime are tuned together"
6. dcode vs Claude Code Architecture
flowchart TB
subgraph DCODE["dcode"]
D1["Any LLM"]
D2["Remote Sandbox"]
D3["LangSmith Tracing"]
D4["AGENTS.md"]
end
subgraph CLAUDE["Claude Code"]
C1["Claude Only"]
C2["Local Execution"]
C3["No Tracing"]
C4["CLAUDE.md"]
end
style DCODE fill:#e8f5e9,stroke:#76b900
style CLAUDE fill:#e3f2fd,stroke:#1a5fb4
Key difference: dcode = model-agnostic + remote sandbox; Claude Code = Claude-locked + local
7. What Lives Where
flowchart TB
subgraph OUTSIDE["OUTSIDE SANDBOX (Host)"]
O1["NemoClaw CLI"]
O2["OpenShell Gateway"]
O3["Policy Engine"]
O4["API Keys"]
O5["Blueprint Resolution"]
end
subgraph INSIDE["INSIDE SANDBOX (Container)"]
I1["Agent Runtime"]
I2["Tools (python, node, git)"]
I3["Agent Memory"]
I4["/sandbox, /tmp (writable)"]
I5["/usr, /lib (read-only)"]
end
Credentials and enforcement on host; execution inside sandbox
8. Network Policy Decision Flow
flowchart LR
REQ["Request"] --> PE["Policy Engine"]
PE --> |"Matches policy"| ALLOW["ALLOW"]
PE --> |"Inference"| ROUTE["ROUTE
(inject creds)"]
PE --> |"No match"| DENY["DENY
(log it)"]
style ALLOW fill:#e8f5e9,stroke:#76b900
style ROUTE fill:#e3f2fd,stroke:#1a5fb4
style DENY fill:#ffebee,stroke:#c62828
Every outbound connection goes through policy engine