integrations/nemo-gym: NeMo Gym sandbox provider built on the Python client - #69
Open
Tomer Glottmann (tomergee) wants to merge 1 commit into
Open
Tomer Glottmann (tomergee) wants to merge 1 commit into
Tomer Glottmann (tomergee) wants to merge 1 commit into
Conversation
…client A NeMo Gym sandbox provider that runs rollout sandboxes as ate-env environments, registered through the nemo_gym.sandbox_providers entry point so Gym-based frameworks (NeMo-RL, Nemotron pipelines) use it without changes. It is a thin adapter over clients/python (ate_env): create and readiness through EnvironmentService plus a shell probe, exec through ProcessService with cwd, env and a guest-side timeout wrapper, file transfer through FileSystemService, status from the environment's lifecycle state so polling never wakes a parked actor, and NOT_FOUND-safe delete. Suspended and paused environments report RUNNING because the router resumes them on the next command, which is what a rollout loop wants. The provider was developed in the substrate repo's demos tree against an earlier ate-env; it moves here because everything it depends on is this repo: the v1alpha API, the Python client, and the guest image. Tests run the real client against an in-process fake of the three services, so they need no cluster (make nemo-gym-test); an end-to-end test runs when SUBSTRATE_E2E_API_URL points at an ate-env-api. The hack/bake-task-image.sh script builds the guest from this checkout by default; the README also shows the OCI image-volume way to add the guest to an unmodified task image.
Collaborator
|
/lgtm |
Jaana Dogan (rakyll)
approved these changes
Oct 2, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
A NeMo Gym sandbox provider that runs rollout sandboxes as ate-env environments, under
integrations/nemo-gym/. It registers through thenemo_gym.sandbox_providersentry point, so Gym-based frameworks (NeMo-RL, Nemotron pipelines) select it with asandbox: substrate:config block and nothing else changes.It is a thin adapter over
clients/python(ate_env):create(spec)Client.createwith the template's atespace, thenEnv.shell("true")until the guest answers, thenEnv.write_fileforspec.filesexec(cmd, cwd=, env=, timeout_s=)Env.start_process(["sh","-c",cmd], cwd, env)+stream_outputs+wait; the deadline is also enforced guest-side withtimeout(1), and on the client-side deadline the process is killed before a-1sentinel result is returnedupload_file/download_fileEnv.write_file/Env.read_file_bytesstatus(handle)Client.get, so polling never wakes a parked actor. Suspended and paused report RUNNING because the router resumes them on the next command; RESUMING is STARTING, CRASHED is ERROR, gone is STOPPEDclose(handle)Client.delete, NOT_FOUND-safeConfig follows ate-env vocabulary (
create.atespace,namespacekept as an alias; defaultsdefault-templateinate-env). Anhttps://api_urlopens a TLS channel; a caller-ownedate_env.Clientcan be passed in.Why here
The provider was developed in the substrate repo's demos tree against an earlier ate-env (HTTP guest proxy,
ateenv.v1stubs). Everything it depends on now is this repo: thev1alphaAPI, the Python client, and the guest image. So it moves here and drops the vendored stubs.Testing
make nemo-gym-test: 35 contract tests run the realate_envclient against an in-process fake of the three services (tests/fakes.py). No cluster, nonemo-gymneeded (base types fall back to structural mirrors; withnemo-gyminstalled the same tests run against the real types).tests/test_e2e.pyruns the full lifecycle on a real actor whenSUBSTRATE_E2E_API_URLpoints at anate-env-api. Not yet run since the port to the gRPC data plane; the README's benchmark numbers are marked as measured on the earlier HTTP path.hack/verify/boilerplate.shpasses.Also in this PR
Makefile:nemo-gym-test.integrations/nemo-gym/hack/bake-task-image.shbuilds the guest from this checkout by default; the README also shows the OCI image-volume way to add the guest to an unmodified task image, which is the shape the SWE-500 benchmark uses.Follow-up
A task-image mode for
ate-envtemplates (guest injected as an image volume) andCreateEnvironmentfrom an image, so the provider'simage_templatesmap stops being a manual step.