加固隔离并通过命令验证。
命令以模板为主,执行前请替换为你自己的 ID、密钥和地址。
每一步都先执行命令,再记录结果和问题。
执行:
export NANOCLAW_SANDBOX=1\ndocker compose up -d
export NANOCLAW_SANDBOX=1docker compose up -d执行:
nanoclaw doctor security\nnanoclaw policy validate
nanoclaw doctor securitynanoclaw policy validate执行:
nanoclaw exec --cmd 'curl http://169.254.169.254'\nExpected: blocked.
nanoclaw exec --cmd 'curl http://169.254.169.254'执行:
tail -n 200 logs/security-audit.log
tail -n 200 logs/security-audit.log