跳转至

OpenShell 后端

OpenShell 生命周期构建在相同的 SSH 传输之上,以及其镜像(mirror)与远程(remote)工作区模式之间的区别。

OpenShell 后端

使用 backend: "openshell" 将工具沙箱化到 OpenShell 管理的远程环境中。OpenShell 复用与通用 SSH 后端相同的 SSH 传输和远程文件系统桥接,并增加了 OpenShell 生命周期管理(sandbox create/get/delete/ssh-config)以及可选的 mirror 工作区同步模式。

{
  agents: {
    defaults: {
      sandbox: {
        mode: "all",
        backend: "openshell",
        scope: "session",
        workspaceAccess: "rw",
      },
    },
  },
  plugins: {
    entries: {
      openshell: {
        enabled: true,
        config: {
          from: "openclaw",
          mode: "remote", // mirror | remote
        },
      },
    },
  },
}

mode: "mirror"(默认)保持本地工作区为权威来源:OpenClaw 在 exec 之前将本地内容同步到沙箱,并在之后同步回来。mode: "remote" 仅从本地初始化远程工作区一次,然后直接对远程工作区执行 exec/read/write/edit/apply_patch,不再同步回来;初始化之后的本地编辑将不可见,直到你执行 openclaw sandbox recreate。在 scope: "agent" 或 scope: "shared" 下,该远程工作区在同一作用域内共享。当前限制:沙箱浏览器尚未支持,且 sandbox.docker.binds 不适用于此后端。

openclaw sandbox list/recreate/prune 都将 OpenShell 运行时与 Docker 运行时同等对待;prune 逻辑是后端感知的。

有关完整的前置要求、配置参考、工作区模式比较和生命周期详细信息,请参阅 OpenShell。

本页原文 Markdown:在 AtomGit 查看·内容源自开源项目 cl/openclaw