Commit Graph
36 Commits
Author SHA1 Message Date
John T. Myers f4dc6be4b2 refactor(inference): remove managed inference routes (#3195)
* refactor(inference): remove managed inference routes

Closes #3172

Remove the inference route control plane, inference.local data path, built-in router crate, and SDK surface. Move inference workloads to explicitly imported provider profiles and native endpoints, with migration cleanup and updated tests and documentation.

Signed-off-by: John Myers <9696606+johntmyers@users.noreply.github.com>

* fix(policy): preserve alternate upstream isolation

Restore the provider policy activation guard so legacy OpenAI and Anthropic providers configured for alternate base URLs do not grant egress to the built-in public vendor endpoints.

Signed-off-by: John Myers <9696606+johntmyers@users.noreply.github.com>

---------

Signed-off-by: John Myers <9696606+johntmyers@users.noreply.github.com>
2026-09-09 18:47:22 +00:00
Russell Bryant 172b65e788 docs: fix first-network-policy sandbox lifecycle flow (#3140)
The tutorial told users to exit the sandbox and reconnect later, but
exiting the interactive shell stops the sandbox's main process and it is
not reconnectable under the default restart policy. Switch to the
two-terminal flow already used by the github-sandbox tutorial so the
sandbox stays running, matching what examples/sandbox-policy-quickstart/
demo.sh actually does.

Related: #2998, #2798

Signed-off-by: Russell Bryant <rbryant@redhat.com>
2026-09-02 21:22:25 +00:00
Johnny Greco 8bc7955263 feat(skills): separate public and contributor workflows (#2899)
* feat(skills): separate public and contributor workflows

Closes #2736

Publish the four user-facing OpenShell skills from the top-level skills directory, mark contributor workflows internal, and update portability guidance, validation, and documentation.

Signed-off-by: Johnny Greco <jogreco@nvidia.com>

* docs(skills): clarify public skill audit scope

Signed-off-by: Johnny Greco <jogreco@nvidia.com>

* docs(skills): use markdown documentation links

Signed-off-by: Johnny Greco <jogreco@nvidia.com>

* docs(skills): align public and contributor guidance

Signed-off-by: Johnny Greco <jogreco@nvidia.com>

---------

Signed-off-by: Johnny Greco <jogreco@nvidia.com>
2026-09-02 16:02:17 +00:00
John T. MyersandJohn Myers 07df822090 feat(providers): make profiles authoritative (#2962)
* feat(providers): make profiles authoritative

Closes #1988

Signed-off-by: John Myers <johntmyers@users.noreply.github.com>

* docs(providers): move profiles into provider navigation

Signed-off-by: John Myers <johntmyers@users.noreply.github.com>

* docs(providers): clarify provider attachment lifecycle

Signed-off-by: John Myers <johntmyers@users.noreply.github.com>

* fix(tui): scroll provider profile picker

Signed-off-by: John Myers <johntmyers@users.noreply.github.com>

* fix(providers): honor profile credential semantics

Signed-off-by: John Myers <johntmyers@users.noreply.github.com>

* fix(providers): prefer exact profile IDs

Signed-off-by: John Myers <johntmyers@users.noreply.github.com>

* fix(providers): harden authoritative profile adoption

Signed-off-by: John Myers <johntmyers@users.noreply.github.com>

* test(oidc): align provider fixtures with profiles

Signed-off-by: John Myers <johntmyers@users.noreply.github.com>

* fix(providers): preserve authoritative profile lifecycle

Signed-off-by: John Myers <johntmyers@users.noreply.github.com>

---------

Signed-off-by: John Myers <johntmyers@users.noreply.github.com>
Co-authored-by: John Myers <johntmyers@users.noreply.github.com>
2026-09-01 19:22:07 +00:00
Simon Scatton 455883905a fix(python): remove CLI from wheel (#2321)
The Maturin-based wheel packaging was a historical remnant from when the local gateway launch path and OpenShell CLI were coupled in one binary. The gateway and CLI now ship as standalone artifacts, so the Python distribution should contain only the SDK.

Build a single platform-independent setuptools wheel, verify that it cannot contain native code or an openshell entry point, and simplify the release jobs and documentation for SDK-only PyPI installs.

Signed-off-by: Simon Scatton <sscatton@nvidia.com>
2026-08-25 13:20:42 +00:00
Matthew Grossman 537805568d feat(sandbox): honor OCI image working directories (#2530)
* feat(sandbox): honor Docker OCI working directories

Signed-off-by: Matthew Grossman <mgrossman@nvidia.com>

* fix(sandbox): honor effective workspace access

Signed-off-by: Matthew Grossman <mgrossman@nvidia.com>

* test(sandbox): cover enforced workspace denial

Signed-off-by: Matthew Grossman <mgrossman@nvidia.com>

* docs(docker): explain effective workdir checks

Signed-off-by: Matthew Grossman <mgrossman@nvidia.com>

* fix(sandbox): validate effective workspace writes

Signed-off-by: Matthew Grossman <mgrossman@nvidia.com>

* fix(sandbox): reserve supervisor control roots

Signed-off-by: Matthew Grossman <mgrossman@nvidia.com>

* refactor(sandbox): centralize control paths

Signed-off-by: Matthew Grossman <mgrossman@nvidia.com>

* fix(sandbox): reserve OCI runtime mount roots

Signed-off-by: Matthew Grossman <mgrossman@nvidia.com>

---------

Signed-off-by: Matthew Grossman <mgrossman@nvidia.com>
2026-08-04 17:38:51 +00:00
Matthew Grossman bc14018cad feat(sandbox): use policy-first OCI image identity (#2509)
* feat(sandbox): use policy-first OCI image identity

Closes #2331

Preserve per-field policy omission, derive Docker and Podman fallbacks from the inspected immutable image, and resolve the final numeric identity before starting agent children.

Signed-off-by: Matthew Grossman <mgrossman@nvidia.com>

* fix(sandbox): preserve declared process identities

Keep explicit policy values and OCI-declared names intact, defer passwd lookup until a primary GID is required, and refresh stale policy examples.

Signed-off-by: Matthew Grossman <mgrossman@nvidia.com>

* fix(supervisor): reuse resolved OCI identity

Signed-off-by: Matthew Grossman <mgrossman@nvidia.com>

* fix(supervisor): allow Linux pre-exec arguments

Signed-off-by: Matthew Grossman <mgrossman@nvidia.com>

* fix(kubernetes): protect resolved sandbox identity

Signed-off-by: Matthew Grossman <mgrossman@nvidia.com>

* fix(sandbox): prepare workspace for OCI identity

Signed-off-by: Matthew Grossman <mgrossman@nvidia.com>

* refactor(sandbox): own only workspace root

Signed-off-by: Matthew Grossman <mgrossman@nvidia.com>

* fix(sandbox): harden partial identity drops

Signed-off-by: Matthew Grossman <mgrossman@nvidia.com>

* test(sandbox): scope OCI image e2e to Docker

Signed-off-by: Matthew Grossman <mgrossman@nvidia.com>

* fix(sandbox): narrow OCI identity fallback scope

Signed-off-by: Matthew Grossman <mgrossman@nvidia.com>

* test(podman): cover OCI identity launch

Signed-off-by: Matthew Grossman <mgrossman@nvidia.com>

* fix(podman): exercise OCI fallback in E2E

Signed-off-by: Matthew Grossman <mgrossman@nvidia.com>

---------

Signed-off-by: Matthew Grossman <mgrossman@nvidia.com>
2026-07-29 05:27:21 +00:00
Matias Schimuneck 2d5652b2d8 docs(docker-compose): replace removed OpenClaw community sandbox with NemoClaw redirect (#2405)
The OpenClaw community sandbox was removed from NVIDIA/OpenShell-Community
in PR #73 (May 16, 2026). The Docker Compose tutorial and docker-compose.yml
comment still referenced the stale --from openclaw command and GHCR image.
Replace the broken OpenClaw tab with a redirect to the NemoClaw Quickstart,
which is the supported path per docs/about/supported-agents.mdx. Remove the
stale pre-pull command for the removed image.
Fixes #2404

Signed-off-by: Matias Schimuneck <schimuneck.matias@gmail.com>
2026-07-22 09:53:37 +00:00
Ignas Baranauskas a72711697d chore: remove deprecated --keep flag from docs, scripts, and e2e tests (#2126)
* docs: remove deprecated --keep flag from tutorials and examples

The --keep flag is deprecated, hidden, and a no-op since sandboxes
are kept by default. Remove references from tutorial docs and example
READMEs that explain it as a real feature.

- Remove --keep from sandbox create commands
- Remove --keep explanation text
- Clarify that sandboxes are kept by default

Signed-off-by: Ignas Baranauskas <ibaranau@redhat.com>

* chore: remove deprecated --keep usage from scripts and e2e tests

The --keep flag is a deprecated no-op since sandboxes are kept by
default. Stop passing it in internal scripts, e2e test scripts,
and example demo scripts.

Signed-off-by: Ignas Baranauskas <ibaranau@redhat.com>

---------

Signed-off-by: Ignas Baranauskas <ibaranau@redhat.com>
2026-07-07 14:36:25 +02:00
Eric Curtin 1c8417c4dd docs(container-gateway): fix Docker driver setup for containerized gateway (#1419)
The existing docs omitted or misstated several requirements when running
the gateway as a container with the Docker compute driver:

- OPENSHELL_GRPC_ENDPOINT is required; the Docker driver uses only the
  scheme (http/https) — host and port are substituted automatically with
  host.openshell.internal and the gateway's own bind port
- Supervisor binary must be extracted to a host path before starting the
  gateway; bind-mount sources are resolved by the host Docker daemon so
  the path must be identical inside and outside the gateway container
- Docker socket access requires adding the docker group (UID 1000 default)
- Port binding should remain 127.0.0.1; Docker driver adds a bridge
  listener automatically
- add --server-san host.openshell.internal to generate-certs for mTLS
- Complete the mTLS docker run with all Docker driver requirements
- Add deploy/docker/gateway.toml — TOML config for the Docker driver
- Add deploy/docker/docker-compose.yml referencing the TOML
- Add docs/get-started/tutorials/docker-compose.mdx tutorial page
- Remote gateway registration instructions (--remote flag)

Address reviewer feedback:
- Move Docker Compose tutorials card to the bottom of the list
- Replace inline YAML snippet in Docker Compose section with a reference
  to deploy/docker/ to avoid drift
- Clarify OPENSHELL_DB_URL is safe in compose.yml (plain SQLite path,
  no credentials); the TOML block targets credential-bearing DSNs
- Note that ./ in source: resolves relative to the compose file directory
- Clarify that only the scheme from OPENSHELL_GRPC_ENDPOINT matters
- Add note that the tilde volume mount resolves to the same absolute
  path on both host and container
2026-06-03 09:41:41 -07:00
Mesut Oezdil f6d0fd175b docs(providers): note that ANTHROPIC_API_KEY requires an API account, not a subscription (#1542)
* docs(providers): note that ANTHROPIC_API_KEY requires an API account, not a subscription

Anthropic subscription users authenticate via OAuth, not an API key,
causing a silent failure when creating the provider. Adds a Note callout
in the provider type table and quickstart guide directing subscription
users to generate an API key from console.anthropic.com.

Closes #620

* docs(providers): fix Note placement and remove subscription brand names

Move the Note callout in manage-providers.mdx to after the complete
provider type table so it does not break table rendering. Remove
subscription brand names from both Note callouts.
2026-05-29 13:15:43 -07:00
Drew Newberry 603b3e27fa docs: update NemoClaw/OpenClaw references (#1529) 2026-05-22 10:31:59 -07:00
John T. Myers 14c5329f91 docs(providers): add Providers v2 guide (#1442)
* docs(providers): add Providers v2 guide

Signed-off-by: John Myers <9696606+johntmyers@users.noreply.github.com>

* docs(providers): clarify built-in profile location

Signed-off-by: John Myers <9696606+johntmyers@users.noreply.github.com>

* docs(providers): remove refresh-backed profile bullet

Signed-off-by: John Myers <9696606+johntmyers@users.noreply.github.com>

* docs(providers): clarify persisted query registry key

Signed-off-by: John Myers <9696606+johntmyers@users.noreply.github.com>

* docs(providers): simplify binary schema example

Signed-off-by: John Myers <9696606+johntmyers@users.noreply.github.com>

* docs(providers): add Microsoft Graph refresh tutorial

Signed-off-by: John Myers <9696606+johntmyers@users.noreply.github.com>

* docs(providers): link Microsoft Graph refresh tutorial

Signed-off-by: John Myers <9696606+johntmyers@users.noreply.github.com>

* docs(providers): announce providers v2

Signed-off-by: John Myers <9696606+johntmyers@users.noreply.github.com>

---------

Signed-off-by: John Myers <9696606+johntmyers@users.noreply.github.com>
2026-05-20 08:57:24 -07:00
Miyoung Choi 8322e4fd00 docs: style fixes (#1341)
* docs: style fixes

* docs: drop observability section overview page and rename a section title

* docs: title updates
2026-05-12 16:36:15 -07:00
Drew Newberry 728165a12c docs: consolidate documentation structure (#1231) 2026-05-07 09:14:08 -07:00
Mesut Oezdil cdfd548af8 docs: replace generic Index link text with actual page titles (#1216)
Four cross-reference links used the label "Index" instead of the
destination page's title, making them ambiguous for readers. Replaced
with the correct titles: "About Gateways and Sandboxes" and "About
Inference Routing".
2026-05-06 15:06:11 -07:00
Drew Newberry f56c09c7df docs: update gateway deployment architecture (#1108) 2026-05-04 22:52:29 -07:00
John T. Myers 6b21804258 feat(policy): add GraphQL L7 inspection (#1083)
Support GraphQL L7 policies
2026-05-04 11:50:09 -07:00
Mesut Oezdil 721c39f1f3 docs: fix tutorial links pointing to /tutorials instead of /get-started/tutorials (#1137) 2026-05-02 13:35:31 -07:00
Mesut Oezdil c0352272e5 docs: fix broken link and capitalise GitHub correctly (#1135)
Close the missing closing parenthesis on the Manage Providers link in
github-sandbox.mdx and correct four instances of "Github" to "GitHub"
across the docs.

Signed-off-by: mesutoezdil <mesudozdil@gmail.com>
2026-05-02 08:06:34 -07:00
Piotr Mlocek df38d1f66f feat(ci): add Markdown and Mermaid linting (#933) 2026-04-24 11:27:02 -07:00
Miyoung Choi 2c9c146cb6 docs: fix TOC structure (#797)
* docs: fix TOC structure

* docs: fix wrong section title

* remove Home

* fix(fern): properly add the landing page
2026-04-17 13:15:29 -07:00
Piotr Mlocek 8b15ef772e docs(fern): move published docs into docs tree (#796)
Remove the legacy Sphinx pipeline and make docs/ the single source of truth so the published site matches the repository layout.
2026-04-09 15:02:27 -07:00
Miyoung Choi 0792dcb425 docs: unify install command in landing page, change docs skill name, update contributing guides (#355) 2026-03-16 07:51:42 -07:00
Drew Newberry 48fd9de521 docs: simplify quickstart install, reorder sections, and clean up sandbox docs (#330) 2026-03-15 18:11:59 -07:00
Miyoung Choi 7230d9cc3d docs: few more bits of docs improvement (#324)
* few more bits of docs improvement

* update docs update skill
2026-03-15 10:46:18 -07:00
Miyoung Choi ed3c44550e docs: improve the docs more (#308)
* improve docs

* save
2026-03-14 16:34:37 -07:00
Miyoung Choi bc25c9b6fe docs: add frontmatter, add json output and search extensions, for improving SEO (#217)
* add frontmatter

* add custom extensions
2026-03-10 18:04:25 -07:00
Miyoung Choi a666b895e5 docs: improve the new revision (#215)
* improve the new revision

* update the animated commands

* more improvements and unifying text

* more fixes
2026-03-10 17:40:17 -07:00
Kirit ThadakaandPiotr Mlocek e57c247bc8 docs: Structural and content updates (#195)
* Removed network access docs

* Simplified docs for sandboxes and inference

* Fixed build

* docs(inference): clarify local inference routing

* docs(inference): update provider and model examples

* docs: add Docker prerequisite warning for connection-refused error

Made-with: Cursor

* Minor edits to quickstart safety and privacy

* Doc restructured

* removed tutorials

* Added tutorial

* Inference section reformatting

* Updated CLI ref

* removed troubleshooting

* Updated inference

* Updated pip install command for bug bash

* Updated arch diagram

* Updated tutorial

* Updated install commands

* Updated getting started

* Updated brev link

---------

Co-authored-by: Piotr Mlocek <pmlocek@nvidia.com>
2026-03-10 12:15:02 -07:00
Drew Newberry 984d1a6e5c chore: rename project from NemoClaw to OpenShell (#198) 2026-03-10 11:49:09 -07:00
Piotr MlocekandMiyoung Choi 107c85d1d7 docs(inference): clarify local inference routing (#190)
* docs(inference): clarify local inference routing

* docs(inference): update provider and model examples

* fix doc build

---------

Co-authored-by: Miyoung Choi <miyoungc@nvidia.com>
2026-03-09 21:34:14 -07:00
Miyoung Choi 95410a065f docs: restructure and polish safety and policy section (#189)
* restructure safty and policy section

* put the table autogeneration back

* enhance generate policy ref doc

* typo
2026-03-09 21:26:35 -07:00
Kirit Thadaka f8d2d824ce docs: Simplified the sandbox docs (#186)
* Removed network access docs

* Simplified docs for sandboxes and inference

* Fixed build
2026-03-09 16:52:30 -07:00
Miyoung Choi 574ef18dfc docs: consolidate information architecture and author content (#124)
* initial doc filling

* improvements

* stage provided get started, and add clean tutorials

* pull in Kirit's content and polish

* improve observability

* moving pieces

* move TOC around

* drop support matrix from concepts

* fix links

* minor fixes and fix badges

* minor fixes

* incorporate missed content

* minor improvements

* clean up

* run dori style guide review

* clean up

* updates impacting docs

* incorporate feedback

* minor fix

* some edits

* enterprise structure

* update cards

* improve

* add some emojis

* improve landing page with animated getting started code

* fix the animated code

* small improvements

* refresh content based on PR 156 and 158

* README as the source of truth for quickstart

* update README

* run edits

* change to the new prod name, text only, code swipe later

* add Home

* incorporate dev feedback on README

* krit's edits

* edit and improve index pages

* fix build

* revert README

* revert quickstart to not pull from README
2026-03-09 11:33:56 -07:00
Miyoung ChoiandDrew Newberry 11f795a462 docs: setup initial docs/ infrastructure and scaffolding (#94)
* set up docs

* rm nv sphinx theme version

* rm v* trigger

* incorporate feedback with cursor

* minor updates

* doc docs

* more small tweaks

* clean contributing

---------

Co-authored-by: Drew Newberry <anewberry@nvidia.com>
2026-03-04 22:31:45 -08:00