Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
42 commits
Select commit Hold shift + click to select a range
eaa90d5
feat(cli): add N1x Express preview
sandl99 Aug 12, 2026
e484c36
fix(onboard): address N1x review findings
sandl99 Aug 12, 2026
39870c4
fix(onboard): keep NIM unavailable on N1x
sandl99 Aug 12, 2026
9d4cb43
docs(inference): document N1x NIM exclusion
sandl99 Aug 12, 2026
3ddf2d8
docs(security): clarify N1x preview boundary
sandl99 Aug 12, 2026
cabda67
Merge branch 'main' into feat/n1x-express-install-8574
cv Aug 12, 2026
e2a1887
Merge branch 'main' into feat/n1x-express-install-8574
cv Aug 12, 2026
d757108
fix(installer): enforce N1x preview boundary
cjagwani Aug 12, 2026
4999de1
fix(installer): refine N1x preview guidance
cjagwani Aug 12, 2026
180df06
Merge branch 'main' into feat/n1x-express-install-8574
sandl99 Aug 13, 2026
82506ca
Merge branch 'main' into feat/n1x-express-install-8574
sandl99 Aug 13, 2026
f9b1699
Merge branch 'main' into feat/n1x-express-install-8574
sandl99 Aug 13, 2026
8287fba
Merge branch 'main' into feat/n1x-express-install-8574
sandl99 Aug 13, 2026
5c79460
Merge branch 'main' into feat/n1x-express-install-8574
sandl99 Aug 13, 2026
54504b0
merge: resolve conflicts with main
github-actions[bot] Aug 13, 2026
46c0be9
test(n1x): format identity link cases
cjagwani Aug 13, 2026
fc3f4e0
merge: resolve conflicts with main
github-actions[bot] Aug 13, 2026
242d561
Merge branch 'main' into feat/n1x-express-install-8574
sandl99 Aug 13, 2026
3eb66af
Merge branch 'main' into feat/n1x-express-install-8574
sandl99 Aug 13, 2026
dbade0d
chore(ci): lower onboard source budget
cv Aug 13, 2026
c803541
fix(test): preserve explicit WSL overrides
cv Aug 13, 2026
d6efd1d
merge(main): refresh N1x Express preview
sandl99 Aug 13, 2026
945a78e
fix(onboard): keep N1x preview on managed vLLM
sandl99 Aug 13, 2026
a5dd019
docs(inference): document N1x port conflict
sandl99 Aug 13, 2026
cbdbbd5
merge(main): refresh N1x Express preview
sandl99 Aug 13, 2026
1bbf27a
fix(hermes): admit the managed API port
prekshivyas Aug 13, 2026
fe09b24
test(onboard): use a valid replacement identity
cv Aug 13, 2026
03865a4
merge: incorporate required main fixes
cv Aug 13, 2026
318ee49
docs(inference): scope N1x vLLM path
sandl99 Aug 13, 2026
e3a112b
Merge remote-tracking branch 'origin/main' into feat/n1x-express-inst…
sandl99 Aug 13, 2026
54905f3
docs(inference): close N1x provider routes
sandl99 Aug 13, 2026
b6a3832
docs(inference): clarify N1x provider boundary
prekshivyas Aug 13, 2026
0ad1bec
docs(platform): state N1x support boundary
sandl99 Aug 13, 2026
19e1245
Merge remote-tracking branch 'origin/feat/n1x-express-install-8574' i…
sandl99 Aug 13, 2026
54c0804
Merge remote-tracking branch 'origin/main' into feat/n1x-express-inst…
sandl99 Aug 13, 2026
e785656
Merge remote-tracking branch 'origin/main' into feat/n1x-express-inst…
sandl99 Aug 13, 2026
0edca58
Merge remote-tracking branch 'origin/main' into feat/n1x-express-inst…
sandl99 Aug 13, 2026
754719d
Merge remote-tracking branch 'origin/main' into feat/n1x-express-inst…
sandl99 Aug 13, 2026
01a231e
Merge remote-tracking branch 'origin/main' into feat/n1x-express-inst…
sandl99 Aug 13, 2026
47e56b3
Merge remote-tracking branch 'origin/main' into feat/n1x-express-inst…
sandl99 Aug 13, 2026
8a2ecdf
docs(e2e): align recovery workflow scope
sandl99 Aug 13, 2026
06aecf4
Merge remote-tracking branch 'origin/main' into feat/n1x-express-inst…
sandl99 Aug 13, 2026
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
16 changes: 12 additions & 4 deletions ci/platform-matrix.json
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
{
"$comment": "SPDX-FileCopyrightText: Copyright (c) 2026 NVIDIA CORPORATION & AFFILIATES. All rights reserved.\nSPDX-License-Identifier: Apache-2.0\n\nSingle source of truth for NemoClaw launch claims and platform support. Covers platforms, inference providers, supported agents, messaging integrations, and deployment paths. Scripts read this to generate README and docs tables. QA/CI update platform/provider rows; the engineering owner reviews other rows. Docs are derived.",
"version": "1.1",
"updated": "2026-08-07",
"updated": "2026-08-12",

"project_status": {
"stage": "alpha",
Expand Down Expand Up @@ -68,6 +68,14 @@
"prerequisites_notes": "Tested with limitations across qualified profiles on one physical DGX Station GB300; see [Additional Setup for DGX Station](additional-setup/dgx-station-preparation) for accepted profiles, the pending no-OTA DGX OS `7.6.x` end-to-end qualification, runtime gates, and current dual-Station and dedicated CI limitations.",
"notes": "The PRD marks this platform as P1. Physical validation on one DGX Station GB300 covers generic Ubuntu 24.04 ARM64, stock DGX OS `7.5.0`, the April 2026 NVIDIA Colossus BaseOS profile, and the June 2026 NVIDIA AI Developer Tools profile. A physical no-OTA DGX OS `7.6.0` host provided the release and hardware profile used for its stable workstation-family classifier and passed read-only eligibility and runtime-command preflight. Full Station Express end-to-end qualification for the accepted no-OTA DGX OS `7.6.x` profile is pending. The profile remains subject to the same physical GB300, driver, ECC, Docker, CDI, and container GPU validation. Clean-host end-to-end validation passed on generic Ubuntu and Colossus BaseOS; stock DGX OS and AI Developer Tools completed Station Express validation. The DGX OS `7.5.0` run used released OpenShell `0.0.85`, local Nemotron Ultra serving, sandbox `cuInit(0)`, and a Hermes write/read file-tool task. A dual-Station configuration has not been validated, and dedicated CI coverage is not available. Direct-GPU policies expose only the exact read-only BDF directory for each discovered display-class PCI device with NVIDIA vendor ID (`0x10de`) and GB300 device ID (`0x31c2` or `0x31c3`) plus required existing topology and module paths; they do not expose `/sys`, the PCI parent subtree, or sysfs write access. During physical validation, reads of `/sys/fs/cgroup/cgroup.controllers` and `/sys/class/net/lo/address` remained denied. For canonical hardware qualification, image requirements, preparation, repair limits, reboot handoff, and the explicit temporary metadata override, see [Prepare DGX Station to Install NemoClaw](../get-started/additional-setup/dgx-station-preparation)."
},
{
"name": "N1x FASTOS",
"runtimes": ["Docker"],
"status": "deferred",
"ci_tested": false,
"prerequisites_notes": "N1x Express remains Deferred until a physical NemoClaw Express E2E test passes. Host identity requires Linux `arm64`, a trusted `/etc/fastos-release` marker with `NAME=\"N1x FASTOS\"`, and NVIDIA display PCI identity `10de:2e2a`. CUDA and Container Device Interface (CDI) readiness are still required.",
"notes": "The accepted Deferred N1x Express preview selects one-host managed vLLM with `nvidia/Qwen3.6-35B-A3B-NVFP4`. It does not activate DGX Spark cluster discovery, the fixed catalog path, managed llama.cpp, or NVIDIA NIM. Host identity requires Linux `arm64`, a regular `/etc/fastos-release` file of 1 through 4,096 bytes that is owned by UID 0 and GID 0, is not a symbolic link, is not group- or world-writable, and contains exactly one `NAME=\"N1x FASTOS\"` line. It also requires NVIDIA display PCI identity `10de:2e2a`. Generic DMI values are supplemental and FastOS version is not pinned. Physical CUDA and CDI checks passed on one N1x host, but full NemoClaw Express E2E validation and dedicated CI coverage are pending. `host.platform.supported` remains absent; only explicit managed-vLLM preview intent can waive the pending-validation finding. Do not claim N1x as supported until that validation passes and this row is promoted."
},
{
"name": "NVIDIA RTX (consumer and Pro workstation GPUs)",
"runtimes": ["Docker"],
Expand Down Expand Up @@ -149,19 +157,19 @@
"name": "Local NVIDIA NIM",
"status": "experimental",
"endpoint_type": "Local OpenAI-compatible",
"notes": "Requires `NEMOCLAW_EXPERIMENTAL=1` and a NIM-capable NVIDIA GPU. Host must have the NVIDIA Container Toolkit installed and a healthy CDI spec. Onboarding evaluates the canonical `host.gpu.nvidia_available`, `host.gpu.container_toolkit_available`, and `host.gpu.cdi_healthy` readiness capabilities before gateway, image, or sandbox lifecycle effects. NIM images pull from `nvcr.io` and require NGC registry login. NemoClaw gates this path behind the experimental flag because it does not auto-select a NIM image for the host today. You must explicitly pick from the validated image list. On Linux arm64 DGX Spark and DGX Station hosts, onboarding warns that some NIM images may not publish a `linux/arm64` manifest; the warning is advisory, and the selected image pull can still fail when the registry has no matching platform manifest. Managed vLLM has host-specific default models and is not gated on the same boxes. Validated images referenced in `src/lib/inference/config.ts` and `nemoclaw/src/index.ts`: `nvidia/nemotron-3-super-120b-a12b` (default cloud model), `nvidia/nemotron-3-nano-30b-a3b`, `nvidia/llama-3.3-nemotron-super-49b-v1.5`."
"notes": "Requires `NEMOCLAW_EXPERIMENTAL=1` and a NIM-capable NVIDIA GPU. Host must have the NVIDIA Container Toolkit installed and a healthy CDI spec. Onboarding evaluates the canonical `host.gpu.nvidia_available`, `host.gpu.container_toolkit_available`, and `host.gpu.cdi_healthy` readiness capabilities before gateway, image, or sandbox lifecycle effects. NIM images pull from `nvcr.io` and require NGC registry login. NemoClaw gates this path behind the experimental flag because it does not auto-select a NIM image for the host today. You must explicitly pick from the validated image list. Local NVIDIA NIM is unavailable on N1x. NemoClaw omits the provider from onboarding and rejects `NEMOCLAW_PROVIDER=nim-local` on N1x. Use the Deferred managed-vLLM preview on N1x. On Linux arm64 DGX Spark and DGX Station hosts, onboarding warns that some NIM images may not publish a `linux/arm64` manifest; the warning is advisory, and the selected image pull can still fail when the registry has no matching platform manifest. Managed vLLM has host-specific default models and is not gated on the same boxes. Validated images referenced in `src/lib/inference/config.ts` and `nemoclaw/src/index.ts`: `nvidia/nemotron-3-super-120b-a12b` (default cloud model), `nvidia/nemotron-3-nano-30b-a3b`, `nvidia/llama-3.3-nemotron-super-49b-v1.5`."
},
{
"name": "Local vLLM (already running)",
"status": "caveated",
"endpoint_type": "Local OpenAI-compatible",
"notes": "Appears in the onboarding menu when NemoClaw detects a server already on `localhost:8000`. No flag required. Model is whatever the existing server serves."
"notes": "Unavailable on N1x. On other hosts, it appears in the onboarding menu when NemoClaw detects a server already on `localhost:8000`. No flag is required. The model is whatever the existing server serves."
},
{
"name": "Local vLLM (managed install/start)",
"status": "caveated",
"endpoint_type": "Local OpenAI-compatible",
"notes": "Appears by default on DGX Spark and qualifying DGX Station GB300 hosts. DGX Station is Tested with limitations across qualified profiles on one physical DGX Station GB300. Full Station Express end-to-end qualification for the accepted no-OTA DGX OS `7.6.x` profile is pending. Dual-Station configurations are not yet validated, and dedicated CI coverage is not available. For canonical Station qualification and host preparation, see the Additional Setup page for [OpenClaw](/user-guide/openclaw/get-started/additional-setup/dgx-station-preparation), [Hermes](/user-guide/hermes/get-started/additional-setup/dgx-station-preparation), or [Deep Agents](/user-guide/deepagents/get-started/additional-setup/dgx-station-preparation). Generic Linux NVIDIA GPU hosts require `NEMOCLAW_EXPERIMENTAL=1` or `NEMOCLAW_PROVIDER=install-vllm`, NVIDIA Container Toolkit, and CDI. NemoClaw pins runtime images to immutable digests. Station Express defaults to `nvidia/NVIDIA-Nemotron-3-Ultra-550B-A55B-NVFP4`; `--station-deepseek` selects `deepseek-ai/DeepSeek-V4-Flash`. Direct managed-vLLM defaults are `nvidia/Qwen3.6-35B-A3B-NVFP4` on DGX Spark, `deepseek-ai/DeepSeek-V4-Flash` on DGX Station, and `nvidia/NVIDIA-Nemotron-3-Nano-4B-FP8` on generic Linux NVIDIA GPU hosts. Image pulls from `nvcr.io` require NGC registry login."
"notes": "Appears by default on DGX Spark and qualifying DGX Station GB300 hosts. A labeled Deferred preview appears on hosts that match the N1x identity requirements; N1x remains Deferred until a physical NemoClaw Express E2E test passes. DGX Station is Tested with limitations across qualified profiles on one physical DGX Station GB300. Full Station Express end-to-end qualification for the accepted no-OTA DGX OS `7.6.x` profile is pending. Dual-Station configurations are not yet validated, and dedicated CI coverage is not available. For canonical Station qualification and host preparation, see the Additional Setup page for [OpenClaw](/user-guide/openclaw/get-started/additional-setup/dgx-station-preparation), [Hermes](/user-guide/hermes/get-started/additional-setup/dgx-station-preparation), or [Deep Agents](/user-guide/deepagents/get-started/additional-setup/dgx-station-preparation). Generic Linux NVIDIA GPU hosts require `NEMOCLAW_EXPERIMENTAL=1` or `NEMOCLAW_PROVIDER=install-vllm`, NVIDIA Container Toolkit, and CDI. NemoClaw pins runtime images to immutable digests. Station Express defaults to `nvidia/NVIDIA-Nemotron-3-Ultra-550B-A55B-NVFP4`; `--station-deepseek` selects `deepseek-ai/DeepSeek-V4-Flash`. Direct managed-vLLM defaults are `nvidia/Qwen3.6-35B-A3B-NVFP4` on DGX Spark and the Deferred N1x preview, `deepseek-ai/DeepSeek-V4-Flash` on DGX Station, and `nvidia/NVIDIA-Nemotron-3-Nano-4B-FP8` on generic Linux NVIDIA GPU hosts. Image pulls from `nvcr.io` require NGC registry login."
}
],

Expand Down
1 change: 1 addition & 0 deletions docs/get-started/prerequisites.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -105,6 +105,7 @@ The table comes from [`ci/platform-matrix.json`](https://github.com/NVIDIA/NemoC
| DGX OS (Station) | Docker | Tested with limitations | Tested with limitations across qualified profiles on one physical DGX Station GB300; see [Additional Setup for DGX Station](additional-setup/dgx-station-preparation) for accepted profiles, the pending no-OTA DGX OS `7.6.x` end-to-end qualification, runtime gates, and current dual-Station and dedicated CI limitations. |
| Linux | Docker | Tested | Primary tested path. Ubuntu 24.04 has host-level onboarding validation. A digest-pinned Ubuntu 26.04 userspace lane builds the CLI and runs preflight, installer, and platform contracts on eligible main pushes; Docker-host, AppArmor, Landlock, and live onboarding validation on 26.04 remain pending. Other distros (Ubuntu 22.04, Fedora, Rocky, Alma, NixOS, Arch) may work but are not validated. |
| macOS (Apple Silicon) | Colima, Docker Desktop | Tested with limitations | Start the container runtime (Colima or Docker Desktop) before installing; NemoClaw verifies the pinned official OpenShell formula and grants formula-scoped trust only around each Homebrew install, inspection, start, or stop operation, requires a legacy or changed formula to be repaired by rerunning the pinned installer, uses the standalone gateway only when Homebrew is absent or both the staged formula and installed keg are absent, requires Homebrew Colima users to install both Colima and the Docker CLI (`brew install colima docker`) before `docker info` can work, and recommends Xcode Command Line Tools (`xcode-select --install`) for Node native modules. |
| N1x FASTOS | Docker | Deferred | N1x Express remains Deferred until a physical NemoClaw Express E2E test passes. Host identity requires Linux `arm64`, a trusted `/etc/fastos-release` marker with `NAME="N1x FASTOS"`, and NVIDIA display PCI identity `10de:2e2a`. CUDA and Container Device Interface (CDI) readiness are still required. |
| Windows WSL2 | Docker Desktop (WSL backend) | Tested with limitations | Requires WSL2 with Docker Desktop backend. See [Additional Setup for Windows Machines](additional-setup/windows-preparation) before the Quickstart. |

For the complete platform support matrix, including all deferred platforms and CI coverage, refer to [Platform Support](../reference/platform-support).
Expand Down
31 changes: 19 additions & 12 deletions docs/get-started/quickstart-hermes.mdx
Original file line number Diff line number Diff line change
Expand Up @@ -39,27 +39,28 @@ Review the [Prerequisites](prerequisites) before you begin.
Run the hosted installer.

```bash
curl -fsSL https://www.nvidia.com/nemoclaw.sh | bash
curl -fsSL https://www.nvidia.com/nemoclaw.sh | NEMOCLAW_AGENT=hermes NEMOCLAW_SANDBOX_NAME=my-hermes bash
```
</Step>

<Step title="Complete Onboarding">
Select **Hermes Agent** when the installer prompts you to choose an agent.
The explicit `NEMOCLAW_AGENT=hermes` setting keeps Hermes selected through interactive or Express setup.

<Note>
On supported platforms, the installer can display `Run express install with these settings? [Y/n]:` before the agent-selection prompt.
On supported platforms other than N1x, the installer can display `Run express install with these settings? [Y/n]:` before ordinary onboarding.
N1x instead displays `Run the Deferred N1x preview with these settings? [Y/n]:`.
Press Enter to use the recommended express install mode for that platform.
This mode applies preset settings and runs the remaining onboarding non-interactively.
Express install mode installs OpenClaw by default.
If you accept, refer to [NemoClaw Quickstart with OpenClaw](/user-guide/openclaw/get-started/quickstart).
Enter `n` if you want to select Hermes, a sandbox name, an inference provider, and a model interactively.
Express install mode preserves the explicit Hermes selection in the install command.
On supported non-N1x express platforms, enter `n` if you want to select a sandbox name, an inference provider, and a model interactively.
On N1x, entering `n` stops installation because the Deferred managed-vLLM preview is the only admitted onboarding path.
Refer to [Use Docker and supported platforms](#use-docker-and-supported-platforms) for more information.
</Note>

When prompted for the sandbox name, enter `my-hermes` or press Enter to accept the suggested `hermes` name.
If you accept the suggested name, use `hermes` instead of `my-hermes` in the commands that follow.
Choose an inference provider and model, then provide its credential when prompted.
For a first run, skip optional web search and messaging setup, then accept the suggested network policy tier.
The install command creates the `my-hermes` sandbox used in the commands that follow.
If you accept Express setup, wait for the installer to finish, then continue with **Confirm the Sandbox Is Ready**; Express selects the provider and model non-interactively.
If the installer does not offer Express setup, or if you enter `n` at the Express prompt on a supported non-N1x host, choose an inference provider and model, then provide its credential when prompted.
For that interactive path, skip optional web search and messaging setup on a first run, then accept the suggested network policy tier.
</Step>

<Step title="Confirm the Sandbox Is Ready">
Expand Down Expand Up @@ -178,10 +179,16 @@ Use these details when your first-run path needs more control.
Before you install from Windows, follow [Prepare a Windows Machine to Install NemoClaw](additional-setup/windows-preparation).
Before you install on DGX Station, follow [Prepare DGX Station to Install NemoClaw](additional-setup/dgx-station-preparation).

DGX Spark, qualifying DGX Station hosts, and Windows Subsystem for Linux (WSL) can offer the recommended express install mode after the third-party software notice.
DGX Spark, qualifying DGX Station, and Windows Subsystem for Linux (WSL) hosts can offer the recommended express install mode after the third-party software notice.
N1x can offer a Deferred preview after the notice, but full physical NemoClaw Express E2E validation is pending.
N1x remains outside the supported-platform set until that validation passes and the platform matrix status is promoted.
Press Enter at the express install prompt to apply preset settings, switch the remaining onboarding to non-interactive mode, and select the managed local inference path for that platform.
Enter `n` to continue with interactive onboarding when you want to select the agent or other settings yourself.
On N1x, accept the preview prompt to apply those settings as explicit Deferred preview intent.
On supported non-N1x express platforms, enter `n` to continue with interactive onboarding when you want to select the agent or other settings yourself.
On N1x, declining the preview or setting only `NEMOCLAW_NO_EXPRESS=1` stops installation before onboarding.
Accept the preview, or set `NEMOCLAW_PROVIDER=install-vllm` before installation to provide the required explicit managed-vLLM intent.
The first Hermes build can take several minutes because NemoClaw builds the Hermes sandbox base image when it is not already cached.
The N1x preview selects one-host managed vLLM with `nvidia/Qwen3.6-35B-A3B-NVFP4`.
Refer to [Set Up vLLM](../inference/local-inference/set-up-vllm) for managed model profiles and headless setup.
Refer to [Set Up vLLM on Two DGX Stations](../inference/local-inference/set-up-vllm-on-two-dgx-stations) for the Deferred paired workflow.
Refer to [Platform Support](../reference/platform-support) for current validation status.
Expand Down
Loading
Loading