Architecture Diagrams Reference

Print-friendly reference of all NemoClaw architecture diagrams

1. Component Hierarchy (Outside to Inside)

flowchart TB subgraph HOST["HOST MACHINE"] DEV["Developer Terminal
> dcode / > nemoclaw"] subgraph NEMOCLAW["NemoClaw (Orchestration Layer)"] CLI["NemoClaw CLI"] BP["Blueprint Resolver"] end subgraph OPENSHELL["OpenShell (Sandbox Layer)"] GW["Gateway"] PE["Policy Engine"] PR["Privacy Router"] end end subgraph SANDBOX["SANDBOX CONTAINER"] subgraph AGENT["Agent (OpenClaw/dcode)"] RT["Runtime"] TOOLS["Tools"] MEM["Memory"] end end subgraph INFERENCE["MODEL"] PROV["Nemotron / Claude / GPT"] end DEV --> CLI --> GW --> SANDBOX AGENT -.->|"inference.local"| PR --> PROV style NEMOCLAW fill:#e8f5e9,stroke:#76b900 style OPENSHELL fill:#e3f2fd,stroke:#1a5fb4 style SANDBOX fill:#fff3e0,stroke:#f57c00

NemoClaw orchestrates → OpenShell sandboxes → Agent executes → Model thinks

2. Five Security Layers (Deny-by-Default)

flowchart LR N["1. NETWORK
Egress rules
SSRF protection"] F["2. FILESYSTEM
Landlock LSM
Read-only paths"] P["3. PROCESS
Capability drops
no-new-privileges"] G["4. GATEWAY
Device auth
Loopback binding"] I["5. INFERENCE
Credential isolation
inference.local"] N --> F --> P --> G --> I style N fill:#e3f2fd,stroke:#1a5fb4 style F fill:#e8f5e9,stroke:#76b900 style P fill:#fff3e0,stroke:#f57c00 style G fill:#f3e5f5,stroke:#7b1fa2 style I fill:#fce4ec,stroke:#c2185b

Mnemonic: "No Funny Paths Get In" (Network, Filesystem, Process, Gateway, Inference)

3. Inference Routing (Credential Isolation)

sequenceDiagram participant A as Agent participant I as inference.local participant O as OpenShell participant C as Credential Store participant M as Model A->>I: Request (no creds) I->>O: Intercept O->>C: Fetch key C-->>O: API key O->>M: Forward (creds injected) M-->>O: Response O-->>A: Response (creds stripped) Note over A,M: Agent NEVER sees API keys

Credentials stay on host, injected at egress, stripped before return

4. The Agent Loop

flowchart LR I["1. INSPECT
Read files"] E["2. EDIT
Modify code"] R["3. RUN
Execute commands"] T["4. TEST
Validate"] S["5. SUMMARIZE
Report"] I --> E --> R --> T --> S S -.->|"If more work"| I

The cycle dcode/OpenClaw follows for each task

5. NemoClaw Blueprint Stack

flowchart TB L1["LangChain Deep Agents (dcode)
Agent Harness"] L2["NVIDIA Nemotron 3 Ultra
Open Model"] L3["NVIDIA OpenShell Runtime
Governed Sandbox"] L1 --> L2 --> L3 style L1 fill:#fff3e0,stroke:#f57c00 style L2 fill:#f3e5f5,stroke:#7b1fa2 style L3 fill:#e3f2fd,stroke:#1a5fb4

"Agent performance improves when model, harness, evals, and runtime are tuned together"

6. dcode vs Claude Code Architecture

flowchart TB subgraph DCODE["dcode"] D1["Any LLM"] D2["Remote Sandbox"] D3["LangSmith Tracing"] D4["AGENTS.md"] end subgraph CLAUDE["Claude Code"] C1["Claude Only"] C2["Local Execution"] C3["No Tracing"] C4["CLAUDE.md"] end style DCODE fill:#e8f5e9,stroke:#76b900 style CLAUDE fill:#e3f2fd,stroke:#1a5fb4

Key difference: dcode = model-agnostic + remote sandbox; Claude Code = Claude-locked + local

7. What Lives Where

flowchart TB subgraph OUTSIDE["OUTSIDE SANDBOX (Host)"] O1["NemoClaw CLI"] O2["OpenShell Gateway"] O3["Policy Engine"] O4["API Keys"] O5["Blueprint Resolution"] end subgraph INSIDE["INSIDE SANDBOX (Container)"] I1["Agent Runtime"] I2["Tools (python, node, git)"] I3["Agent Memory"] I4["/sandbox, /tmp (writable)"] I5["/usr, /lib (read-only)"] end

Credentials and enforcement on host; execution inside sandbox

8. Network Policy Decision Flow

flowchart LR REQ["Request"] --> PE["Policy Engine"] PE --> |"Matches policy"| ALLOW["ALLOW"] PE --> |"Inference"| ROUTE["ROUTE
(inject creds)"] PE --> |"No match"| DENY["DENY
(log it)"] style ALLOW fill:#e8f5e9,stroke:#76b900 style ROUTE fill:#e3f2fd,stroke:#1a5fb4 style DENY fill:#ffebee,stroke:#c62828

Every outbound connection goes through policy engine