Commit Graph
25 Commits
Author SHA1 Message Date
Johnny Greco 87929ad130 docs: keep page URLs aligned with file paths (#3713)
* docs: align page file names and nav labels with published URLs

Signed-off-by: Johnny Greco <jogreco@nvidia.com>

* docs: redirect moved dev pages and fix agent guide redirects

Signed-off-by: Johnny Greco <jogreco@nvidia.com>

* ci(docs): check that page URLs match their file paths

Signed-off-by: Johnny Greco <jogreco@nvidia.com>

* fix(docs): align navigation checks with repo conventions

Signed-off-by: Johnny Greco <jogreco@nvidia.com>

* docs: omit historical redirect aliases

Signed-off-by: Johnny Greco <jogreco@nvidia.com>

* fix(docs): preserve published overview and TypeScript URLs

Signed-off-by: Johnny Greco <jogreco@nvidia.com>

* fix(docs): redirect unversioned overview and TypeScript URLs

Signed-off-by: Johnny Greco <jogreco@nvidia.com>

---------

Signed-off-by: Johnny Greco <jogreco@nvidia.com>
2026-09-28 02:08:54 +00:00
Johnny Greco f155899527 docs(tutorials): run Pi with OpenRouter (#3722)
* docs(tutorials): run Pi with OpenRouter

Switch the Pi tutorial from Anthropic to OpenRouter, add fd to the Pi image
so Pi does not try to download it from GitHub inside the sandbox, and rename
the page to Run Pi with OpenRouter with a dev redirect from the old URL.

Signed-off-by: Johnny Greco <jogreco@nvidia.com>

* docs(tutorials): drop redirect for dev-only Pi page

Signed-off-by: Johnny Greco <jogreco@nvidia.com>

* docs(tutorials): make the Pi tutorial easier to follow

Add prerequisites and steps, explain providers and the profile fields in
plain terms, inspect the sandbox while Pi is still running, and add clean-up
and troubleshooting sections.

Signed-off-by: Johnny Greco <jogreco@nvidia.com>

* docs(tutorials): clarify Pi's providers and sandbox additions

Signed-off-by: Johnny Greco <jogreco@nvidia.com>

* docs(tutorials): make the Pi tutorial more conversational

Signed-off-by: Johnny Greco <jogreco@nvidia.com>

---------

Signed-off-by: Johnny Greco <jogreco@nvidia.com>
2026-09-26 01:38:59 +00:00
Johnny Greco d7f921190b docs(policy): refresh policy documentation and references (#3563)
* docs(policy): correct schema and default policy guidance

Signed-off-by: Johnny Greco <jogreco@nvidia.com>

* docs(policy): add network recipes and update command reference

Signed-off-by: Johnny Greco <jogreco@nvidia.com>

* docs(policy): organize lifecycle guidance and troubleshooting

Signed-off-by: Johnny Greco <jogreco@nvidia.com>

* docs(policy): split policy overview into concepts and management tasks

Signed-off-by: Johnny Greco <jogreco@nvidia.com>

* docs(policy): reorganize network recipes as a cookbook

Signed-off-by: Johnny Greco <jogreco@nvidia.com>

* docs(policy): restructure schema reference by field group and protocol

Signed-off-by: Johnny Greco <jogreco@nvidia.com>

* docs(policy): align troubleshooting, advisor, and reference pages

Signed-off-by: Johnny Greco <jogreco@nvidia.com>

* docs(policy): fix first policy tutorial and security guidance

Signed-off-by: Johnny Greco <jogreco@nvidia.com>

* docs(policy): keep overview high level and move network rules to their own page

Signed-off-by: Johnny Greco <jogreco@nvidia.com>

* docs(policy): focus policy management on CLI workflows and remove command reference

Signed-off-by: Johnny Greco <jogreco@nvidia.com>

* docs(policy): clarify policy views and sandbox deletion in management guide

Signed-off-by: Johnny Greco <jogreco@nvidia.com>

* docs(policy): streamline network rule concepts and examples

Signed-off-by: Johnny Greco <jogreco@nvidia.com>

* docs(policy): correct request path wildcard semantics

Signed-off-by: Johnny Greco <jogreco@nvidia.com>

* docs(policy): rewrite policy advisor guide for clarity

Signed-off-by: Johnny Greco <jogreco@nvidia.com>

* docs(policy): clarify policy advisor scope, setup, and review

Signed-off-by: Johnny Greco <jogreco@nvidia.com>

* docs(policy): rewrite policy prover guide for clarity

Signed-off-by: Johnny Greco <jogreco@nvidia.com>

* docs(policy): explain the two uses of the policy prover

Signed-off-by: Johnny Greco <jogreco@nvidia.com>

* docs(policy): describe policy prover uses, boundaries, and coverage

Signed-off-by: Johnny Greco <jogreco@nvidia.com>

* docs(policy): place prover before advisor and troubleshooting last

Signed-off-by: Johnny Greco <jogreco@nvidia.com>

* docs(policy): remove unsupported CI guidance from prover page

Signed-off-by: Johnny Greco <jogreco@nvidia.com>

* docs(policy): tighten policy prover introduction

Signed-off-by: Johnny Greco <jogreco@nvidia.com>

* docs(policy): move policy change behavior into management guide

Signed-off-by: Johnny Greco <jogreco@nvidia.com>

* docs(policy): name prover check types and note expanding coverage

Signed-off-by: Johnny Greco <jogreco@nvidia.com>

* docs(policy): prefix prover and advisor sidebar labels

Signed-off-by: Johnny Greco <jogreco@nvidia.com>

* docs(policy): streamline policy schema reference

Signed-off-by: Johnny Greco <jogreco@nvidia.com>

* docs(policy): place default policy before schema reference

Signed-off-by: Johnny Greco <jogreco@nvidia.com>

* docs(policy): fold troubleshooting into policy management guide

Signed-off-by: Johnny Greco <jogreco@nvidia.com>

* docs(policy): correct tutorial log samples and GitHub push policy steps

The first policy tutorial said the 403 body begins with error, policy, and
rule, but the proxy serializes the body with sorted keys. Its log samples also
showed the wrong CONNECT deny reason for a sandbox without network rules, and
the L7 deny sample omitted the :443 authority, the `l7` engine, and the reason
tag that the shorthand formatter emits.

The GitHub tutorial filtered denials with `--level warn`, which hides the INFO
level OCSF policy events, and showed the retired key=value log format. Its
hand-written policy also omitted /bin from the restrictive default, so
`policy set` would reject the file for removing a filesystem path on a live
sandbox. Start from `policy get --base` and add only the network rules.

Signed-off-by: Johnny Greco <jogreco@nvidia.com>

* docs(policy): improve flow and terminology across policy pages

Signed-off-by: Johnny Greco <jogreco@nvidia.com>

* docs(policy): correct network rule matching and protocol details

Signed-off-by: Johnny Greco <jogreco@nvidia.com>

* docs(policy): align policy management steps with CLI behavior

Signed-off-by: Johnny Greco <jogreco@nvidia.com>

* docs(policy): correct policy advisor proposal and approval details

Signed-off-by: Johnny Greco <jogreco@nvidia.com>

* docs(policy): correct policy section, default, and schema details

Signed-off-by: Johnny Greco <jogreco@nvidia.com>

* docs(policy): correct prover installation and coverage limits

Signed-off-by: Johnny Greco <jogreco@nvidia.com>

* docs(policy): recommend tls skip for server-first protocols

Signed-off-by: Johnny Greco <jogreco@nvidia.com>

* docs(policy): fix stale baseline path and interpreter examples

Signed-off-by: Johnny Greco <jogreco@nvidia.com>

* docs(policy): move policy pages under how-it-works and fix links

Signed-off-by: Johnny Greco <jogreco@nvidia.com>

* docs(policy): align native TCP guidance in security best practices

Signed-off-by: Johnny Greco <jogreco@nvidia.com>

* docs(policy): restore policy.local and policy DNS details from main

Signed-off-by: Johnny Greco <jogreco@nvidia.com>

* docs(policy): state exact glob matching rules

Signed-off-by: Johnny Greco <jogreco@nvidia.com>

---------

Signed-off-by: Johnny Greco <jogreco@nvidia.com>
2026-09-25 18:19:16 +00:00
Drew Newberry 9244868056 docs: refresh architecture and agent guides (#3705)
* docs: refresh architecture and agent guides

Signed-off-by: Drew Newberry <anewberry@nvidia.com>

* docs: describe updated security architecture neutrally

Signed-off-by: Drew Newberry <anewberry@nvidia.com>

* docs: highlight new isolation primitives

Signed-off-by: Drew Newberry <anewberry@nvidia.com>

* docs(sandboxes): clarify how to disconnect

Signed-off-by: Drew Newberry <anewberry@nvidia.com>

* docs: align architecture and guides with current navigation

Signed-off-by: Drew Newberry <anewberry@nvidia.com>

* docs(extensibility): streamline extension authentication guidance

Signed-off-by: Drew Newberry <anewberry@nvidia.com>

---------

Signed-off-by: Drew Newberry <anewberry@nvidia.com>
2026-09-25 02:38:00 -07:00
Miyoung Choi 2c9c146cb6 docs: fix TOC structure (#797)
* docs: fix TOC structure

* docs: fix wrong section title

* remove Home

* fix(fern): properly add the landing page
2026-04-17 13:15:29 -07:00
Piotr Mlocek 8b15ef772e docs(fern): move published docs into docs tree (#796)
Remove the legacy Sphinx pipeline and make docs/ the single source of truth so the published site matches the repository layout.
2026-04-09 15:02:27 -07:00
John T. Myers f37b69b5e5 feat(sandbox): auto-detect TLS and terminate unconditionally for credential injection (#544)
* feat(sandbox): auto-detect TLS and terminate unconditionally for credential injection

Closes #533

The proxy now auto-detects TLS by peeking the first bytes of each
connection. When TLS is detected, it terminates unconditionally —
enabling credential injection and optional L7 inspection without
requiring explicit 'tls: terminate' in the policy.
2026-03-23 18:45:18 -07:00
Parth Sareen 86a8fa13e0 docs(ollama): fix references to renamed tutorial file (#513) 2026-03-20 15:29:21 -07:00
Parth Sareen ba19aade08 docs(ollama): update ollama tutorial and references to match latest (#511)
features
2026-03-20 14:42:54 -07:00
Parth Sareen efb80e7382 docs(ollama): add ollama to community sandboxes catalog and supported agents (#383)
* docs(ollama): add ollama to community sandboxes catalog and supported agents

* update readme
2026-03-17 14:02:40 -07:00
Piotr Mlocek 00ae3edb5b fix(docs): resolve Pygments console lexer error in LM Studio tutorial (#402)
The console lexer cannot tokenize single-quoted JSON arguments in
multi-line shell commands. Switch the Step 5 code blocks to the bash
lexer which handles quoting correctly. Also standardize earlier blocks
to use the console lexer with $ prompts for simple commands, and
replace -H/-d curl flags with --json for consistency.
2026-03-17 10:45:36 -07:00
will-lms 0463046ad0 docs(inference): Add LM Studio guide (#386)
Signed-off-by: Will Burford <will@lmstudio.ai>
2026-03-16 21:30:42 -07:00
Piotr Mlocek 85903b95e0 docs: add debug-inference skill, Ollama tutorial, and remove stale inference policy references (#353) 2026-03-16 07:26:25 -07:00
Miyoung ChoiandKirit93 c420109a6a docs: add dedicated gateway docs, network policy tutorial, and license page (#294)
* Added gateway and tutorial

* add new content and polish, add license terms

* small fix

* tiny fix

* polish bit more

* change warning to important

* fix support matrix

* small fix

* add a note about example script

* fix link

* fix link

* improve

* fix links

* unclutter sandbax index more

* improve titles

* tiny style fix

* style guide on inferences, release notes link to gh

* polish

* nit

* switch version to 0.0.3

* incorporate feedback

---------

Co-authored-by: Kirit93 <kthadaka@nvidia.com>
2026-03-14 09:53:01 -07:00
Drew Newberry 7b0a243304 ci: remove sandbox docker build from publish and e2e workflows (#275) 2026-03-13 00:56:07 -07:00
Piotr Mlocek 14e296d318 fix(cli): add --no-keep for ephemeral sandbox create cleanup (#258) 2026-03-12 17:18:39 -07:00
Miyoung Choi a453aa7a4e docs: improve tutorial and edit per nv style guide (#240)
* edit tutorial per nv style guide

* few more edits

* iron out a bit more

* rephrase prereqs

* iron out policy update section

* improve update policy section

* nit

* rebase and improve

* merge the new policy update steps finalized with Kirit

* Kirit's change requests
2026-03-12 08:49:00 -07:00
Kirit Thadaka 4b6228895b Updated tutorial formatting (#250) 2026-03-11 20:04:03 -07:00
Kirit Thadaka 71684e0598 Update tutorial prereqs (#235) 2026-03-11 11:43:13 -07:00
Kirit Thadaka 47c4dad0d9 Updated tutorial name (#224) 2026-03-10 23:10:32 -07:00
Kirit Thadaka 564c6a9cc7 docs: Updated tutorial (#223)
* Updated tutorial

* Updated tutorial formatting
2026-03-10 22:50:21 -07:00
Miyoung Choi bc25c9b6fe docs: add frontmatter, add json output and search extensions, for improving SEO (#217)
* add frontmatter

* add custom extensions
2026-03-10 18:04:25 -07:00
Miyoung Choi a666b895e5 docs: improve the new revision (#215)
* improve the new revision

* update the animated commands

* more improvements and unifying text

* more fixes
2026-03-10 17:40:17 -07:00
Drew Newberry f4af0ee848 chore: replace all nemoclaw references with openshell (#214)
- Update registry URLs from ghcr.io/nvidia/nemoclaw to ghcr.io/nvidia/openshell
- Rename NEMOCLAW_* environment variables to OPENSHELL_*
- Update CLI command references in documentation
- Update PyPI package name references
- Update GitHub repository URLs
- Rename .agents/skills/nemoclaw-cli directory to openshell-cli
2026-03-10 16:10:57 -07:00
Kirit ThadakaandPiotr Mlocek e57c247bc8 docs: Structural and content updates (#195)
* Removed network access docs

* Simplified docs for sandboxes and inference

* Fixed build

* docs(inference): clarify local inference routing

* docs(inference): update provider and model examples

* docs: add Docker prerequisite warning for connection-refused error

Made-with: Cursor

* Minor edits to quickstart safety and privacy

* Doc restructured

* removed tutorials

* Added tutorial

* Inference section reformatting

* Updated CLI ref

* removed troubleshooting

* Updated inference

* Updated pip install command for bug bash

* Updated arch diagram

* Updated tutorial

* Updated install commands

* Updated getting started

* Updated brev link

---------

Co-authored-by: Piotr Mlocek <pmlocek@nvidia.com>
2026-03-10 12:15:02 -07:00