Files
OpenShell/docs/get-started/tutorials/index.mdx
John T. Myers f4dc6be4b2 refactor(inference): remove managed inference routes (#3195)
* refactor(inference): remove managed inference routes

Closes #3172

Remove the inference route control plane, inference.local data path, built-in router crate, and SDK surface. Move inference workloads to explicitly imported provider profiles and native endpoints, with migration cleanup and updated tests and documentation.

Signed-off-by: John Myers <9696606+johntmyers@users.noreply.github.com>

* fix(policy): preserve alternate upstream isolation

Restore the provider policy activation guard so legacy OpenAI and Anthropic providers configured for alternate base URLs do not grant egress to the built-in public vendor endpoints.

Signed-off-by: John Myers <9696606+johntmyers@users.noreply.github.com>

---------

Signed-off-by: John Myers <9696606+johntmyers@users.noreply.github.com>
2026-09-09 18:47:22 +00:00

46 lines
1.8 KiB
Plaintext

---
# SPDX-FileCopyrightText: Copyright (c) 2025-2026 NVIDIA CORPORATION & AFFILIATES. All rights reserved.
# SPDX-License-Identifier: Apache-2.0
title: "Tutorials"
slug: "get-started/tutorials"
description: "Step-by-step walkthroughs for OpenShell, from first sandbox to production-ready policies."
keywords: "Generative AI, Cybersecurity, Tutorial, Sandbox, Policy"
position: 1
---
Hands-on walkthroughs that teach OpenShell concepts by building real configurations. Each tutorial builds on the previous one, starting with core sandbox mechanics and progressing to production workflows.
<Cards>
<Card title="First Network Policy" href="/get-started/tutorials/first-network-policy">
Create a sandbox, observe default-deny networking, apply a read-only L7 policy, and inspect audit logs. No AI agent required.
</Card>
<Card title="GitHub Push Access" href="/get-started/tutorials/github-sandbox">
Launch Claude Code in a sandbox, diagnose a policy denial, and iterate on a custom GitHub policy from outside the sandbox.
</Card>
<Card title="Microsoft Graph Provider Refresh" href="/get-started/tutorials/microsoft-graph-provider-refresh">
Configure a Microsoft Graph provider profile with gateway-managed OAuth2 refresh-token rotation.
</Card>
<Card title="Inference with Ollama" href="/get-started/tutorials/inference-ollama">
Run Ollama models in a community sandbox or attach a profile for a host-level service.
</Card>
<Card title="Local Inference with LM Studio" href="/get-started/tutorials/local-inference-lmstudio">
Attach an endpoint-bearing profile and call a local LM Studio server directly.
</Card>
<Card title="Docker Compose Setup" href="/get-started/tutorials/docker-compose">
Run the OpenShell gateway as a Docker Compose service and create agent sandboxes including OpenClaw.
</Card>
</Cards>