Harden isolation and verify with tests.
Commands are templates. Replace IDs, secrets and endpoints with your environment values.
Execute each command, capture output, then note issues and fixes.
Run:
export NANOCLAW_SANDBOX=1\ndocker compose up -d
export NANOCLAW_SANDBOX=1docker compose up -dRun:
nanoclaw doctor security\nnanoclaw policy validate
nanoclaw doctor securitynanoclaw policy validateRun:
nanoclaw exec --cmd 'curl http://169.254.169.254'\nExpected: blocked.
nanoclaw exec --cmd 'curl http://169.254.169.254'Run:
tail -n 200 logs/security-audit.log
tail -n 200 logs/security-audit.log