Server, CLI and rail library
The NeMo Guardrails CLI is the nemoguardrails command installed with the package: it chats with a config folder, serves configs over HTTP, and the package also ships a library of ready-made rails.
Last updated: 30 Sep, 2026 · NeMo Guardrails 0.24.1
This course used NeMo from Python, one config at a time. The same package runs as a server, and NeMo is one of several guardrail frameworks, which the video compares before choosing it.
The clip names four ways to add guardrails: NeMo Guardrails from NVIDIA, Guardrails AI, Llama Firewall from Meta, and AWS Bedrock Guardrails, a cloud-native service. Choose by use case, and by open source or paid.
Syntax:
nemoguardrails chat --config=. # talk to a config folder in the terminal
nemoguardrails server --config=configs # serve every folder in configs/ over HTTPThe commands
import subprocess
import sys
out = subprocess.run([sys.executable, "-m", "nemoguardrails", "--help"],
capture_output=True, text=True).stdout
for name in ["chat", "server", "actions-server", "eval", "convert"]:
print(name, name in out)chat True server True actions-server True eval True convert True
- chat opens an interactive conversation with a folder, handy for trying rails by hand.
- server starts an HTTP server with an OpenAI-style chat endpoint, so other applications call your rails.
- actions-server runs actions in a separate process; eval evaluates a config; convert moves Colang 1.0 files to 2.x.
The rail library
import os
import nemoguardrails.library as library
folders = sorted(name for name in os.listdir(os.path.dirname(library.__file__))
if not name.startswith("_") and "." not in name)
print(len(folders))
print(", ".join(folders))32 activefence, ai_defense, attention, autoalign, clavata, cleanlab, content_safety, context_bloat_detection, crowdstrike_aidr, f5, factchecking, fiddler, gcp_moderate_text, gliner, guardrails_ai, hallucination, hf_classifier, injection_detection, jailbreak_detection, llama_guard, pangea, patronusai, policyai, polygraf, privateai, prompt_security, regex, self_check, sensitive_data_detection, topic_safety, trend_micro, utils
self_check is where self check input came from. jailbreak_detection, injection_detection, content_safety, llama_guard and sensitive_data_detection cover what this course wrote by hand, with models trained for the job. Each is switched on as self check input was: a flow name in config.yml, plus whatever model or key it needs.
Guardrail frameworks compared
| Framework | By | Rules written as | Runs |
|---|---|---|---|
| NeMo Guardrails | NVIDIA | Colang flows and Python actions | Self-hosted, open source |
| Guardrails AI | Guardrails AI | Python validators | Self-hosted or their cloud |
| Llama Firewall / Llama Guard | Meta | A model trained to classify | Self-hosted, open weights |
| AWS Bedrock Guardrails | Amazon | Console or API settings | AWS, paid per call |
Where each fits
- NeMo when the rules should be readable files, with your own flows and actions.
- A trained classifier, such as Llama Guard from the rail library, when paraphrased attacks matter more than cost.
colang_version defaults to 1.0, which this course uses; 2.x examples in the documentation do not run in a 1.0 config.Related
- Previous: Groq or Gemini
- Next: Every rail in one config
- Reference: Guardrail catalog
- Run
nemoguardrails chat --config=.in the folder from config.py on disk. - Open
library/jailbreak_detectionand find the flow names it defines.
Slow is fine. Stopping is the only problem.