BACK TO ALL BUILDSSYSTEM_DOSSIER // 03
Autonomous Agent Infrastructure
FLAGSHIP SYSTEM
NemoClaw Agent Watchdog & Linux Sandbox
Zero-dependency health daemon & Landlock container isolation runtime
System Overview
A zero-dependency health watchdog, incident logging daemon, and Linux Landlock/Capsh container security sandbox for multi-agent LLM runtimes (Hermes, OpenClaw). Monitors container memory and socket health, dispatching instant telemetry to Discord and ntfy.sh.
Architectural Decisions & Build Log
Engineered to manage persistent autonomous agent fleets on Fedora Linux without giving LLMs unchecked access to the host machine.
ENGINEERING SPECIFICATIONS
POSIX ACL automatic inheritance allowing unprivileged sandbox containers to write to shared Obsidian vaults.
Layer-7 Open Policy Agent supervisor proxy blocking unauthorized network egress.
Tailscale Serve integration providing secure TLS web dashboards across remote devices.
LESSONS LEARNED & TAKEAWAYS
▸Autonomous agent runtimes require kernel-level sandboxing, not just Docker containerization.
▸Multi-agent concurrent ports must be dynamically offset to prevent gateway port collisions.
TECHNOLOGIES & RUNTIMES
Python 3.13DockerLandlock / CapshOpenShellSystemdTailscale HTTPS