# Sandboxing and memory

> Sandbox modes, host folder binds, and how agent memory persists

- 网址：https://funcoding.ai/agents/openclaw/help/faq/sandboxing-and-memory/
- 来源：OpenClaw 官方文档原文（英文），MIT 许可，同步于 2026-10-11
- 官方原文：https://docs.openclaw.ai/zh-CN/help/faq/sandboxing-and-memory

---
## Sandboxing and memory

<details>
<summary>Is there a dedicated sandboxing doc?</summary>

Yes: [Sandboxing](https://funcoding.ai/agents/openclaw/gateway/sandboxing/). For Docker-specific setup (full gateway in Docker or sandbox images), see [Docker](https://funcoding.ai/agents/openclaw/install/docker/).

</details>

<details>
<summary>Docker feels limited - how do I enable full features?</summary>

The default image is security-first and runs as the `node` user, so it excludes system packages, Homebrew, and bundled browsers. For a fuller setup:

- Persist `/home/node` with `OPENCLAW_HOME_VOLUME` so caches survive.
- Bake system deps into the image with `OPENCLAW_IMAGE_APT_PACKAGES`.
- Bake Playwright Chromium and its system dependencies into the image with `OPENCLAW_INSTALL_BROWSER=1`.

Docs: [Docker](https://funcoding.ai/agents/openclaw/install/docker/), [Browser](https://funcoding.ai/agents/openclaw/tools/browser/).

</details>

<details>
<summary>Can I keep DMs personal but make groups public/sandboxed with one agent?</summary>

Yes, if private traffic is **DMs** and public traffic is **groups**. Set `agents.defaults.sandbox.mode: "non-main"` so group/channel sessions (non-main keys) run in the configured sandbox backend while the main DM session stays on-host. Select `backend: "docker"` for Docker or `backend: "podman"` for Podman. Restrict tools available in sandboxed sessions via `tools.sandbox.tools`.

Setup walkthrough: [Groups: personal DMs + public groups](https://funcoding.ai/agents/openclaw/channels/groups/#pattern-personal-dms-public-groups-single-agent). Key reference: [Gateway configuration](https://funcoding.ai/agents/openclaw/gateway/config-agents/sandbox/#agentsdefaultssandbox).

</details>

<details>
<summary>How do I bind a host folder into the sandbox?</summary>

Set `agents.defaults.sandbox.docker.binds` to `["host:container:mode"]` (for example `"/home/user/src:/src:ro"`). Global and per-agent binds merge; per-agent binds are ignored when `scope: "shared"`. Use `:ro` for anything sensitive; binds bypass the sandbox filesystem walls.

OpenClaw validates bind sources against both the normalized path and the canonical path resolved through the deepest existing ancestor, so symlink-parent escapes fail closed even when the final path segment does not exist yet.

See [Sandboxing](https://funcoding.ai/agents/openclaw/gateway/sandboxing/#multiple-folders-for-one-agent) and [Sandbox vs Tool Policy vs Elevated](https://funcoding.ai/agents/openclaw/gateway/sandbox-vs-tool-policy-vs-elevated/#bind-mounts-security-quick-check).

</details>

<details>
<summary>How does memory work?</summary>

OpenClaw memory is Markdown files in the agent workspace: daily notes in `memory/YYYY-MM-DD.md`, curated long-term notes in `MEMORY.md` (main/private sessions only).

OpenClaw also runs a silent **pre-compaction memory flush** before compaction summarizes the conversation, reminding the model to write durable notes first. It only runs when the workspace is writable (read-only sandboxes skip it); disable with `agents.defaults.compaction.memoryFlush.enabled: false`. See [Memory](https://funcoding.ai/agents/openclaw/concepts/memory/).

</details>

<details>
<summary>Memory keeps forgetting things. How do I make it stick?</summary>

Ask the bot to **write the fact to memory**: long-term notes go in `MEMORY.md`, short-term context in `memory/YYYY-MM-DD.md`. Reminding the model to store memories usually resolves it. If it keeps forgetting, verify the Gateway uses the same workspace on every run.

Docs: [Memory](https://funcoding.ai/agents/openclaw/concepts/memory/), [Agent workspace](https://funcoding.ai/agents/openclaw/concepts/agent-workspace/).

</details>

<details>
<summary>Does memory persist forever? What are the limits?</summary>

Memory files live on disk and persist until deleted; the limit is your storage, not the model. **Session context** is still limited by the model context window, so long conversations can compact or truncate - that is why memory search exists, pulling only the relevant parts back into context.

Docs: [Memory](https://funcoding.ai/agents/openclaw/concepts/memory/), [Context](https://funcoding.ai/agents/openclaw/concepts/context/).

</details>

<details>
<summary>Does semantic memory search require an OpenAI API key?</summary>

No. **OpenAI embeddings**, the default provider, can use a stored Codex OAuth profile when the account grants embedding access, or an API key (`OPENAI_API_KEY` or `models.providers.openai.apiKey`). The separate Sign in with ChatGPT token-sharing grant does not authorize embeddings. Run `openclaw memory status --deep` to check your configured account.

To stay local, set `memory.search.provider: "local"` (GGUF/llama.cpp). Other supported providers: Bedrock, DeepInfra, Gemini (`GEMINI_API_KEY` or `memory.search.remote.apiKey`), GitHub Copilot, LM Studio, Mistral, Ollama, OpenAI-compatible, and Voyage. See [Memory](https://funcoding.ai/agents/openclaw/concepts/memory/) and [Memory search](https://funcoding.ai/agents/openclaw/concepts/memory-search/) for setup details.

</details>
