Files
OpenShell/docs/index.mdx
John T. Myers f4dc6be4b2 refactor(inference): remove managed inference routes (#3195)
* refactor(inference): remove managed inference routes

Closes #3172

Remove the inference route control plane, inference.local data path, built-in router crate, and SDK surface. Move inference workloads to explicitly imported provider profiles and native endpoints, with migration cleanup and updated tests and documentation.

Signed-off-by: John Myers <9696606+johntmyers@users.noreply.github.com>

* fix(policy): preserve alternate upstream isolation

Restore the provider policy activation guard so legacy OpenAI and Anthropic providers configured for alternate base URLs do not grant egress to the built-in public vendor endpoints.

Signed-off-by: John Myers <9696606+johntmyers@users.noreply.github.com>

---------

Signed-off-by: John Myers <9696606+johntmyers@users.noreply.github.com>
2026-09-09 18:47:22 +00:00

140 lines
4.4 KiB
Plaintext

---
# SPDX-FileCopyrightText: Copyright (c) 2025-2026 NVIDIA CORPORATION & AFFILIATES. All rights reserved.
# SPDX-License-Identifier: Apache-2.0
title: "NVIDIA OpenShell Developer Guide"
description: "OpenShell is the safe, private runtime for autonomous AI agents. Run agents in sandboxed environments that protect your data, credentials, and infrastructure."
keywords: "Generative AI, Cybersecurity, AI Agents, Sandboxing, Security, Privacy, Provider Credentials"
position: 1
---
import { BadgeLinks } from "./_components/BadgeLinks";
import { CommandTerminal } from "./_components/CommandTerminal";
<BadgeLinks
badges={[
{
href: "https://github.com/NVIDIA/OpenShell",
src: "https://img.shields.io/badge/github-repo-green?logo=github",
alt: "GitHub",
},
{
href: "https://github.com/NVIDIA/OpenShell/blob/main/LICENSE",
src: "https://img.shields.io/badge/License-Apache_2.0-blue",
alt: "License",
},
{
href: "https://pypi.org/project/openshell/",
src: "https://img.shields.io/badge/PyPI-openshell-orange?logo=pypi",
alt: "PyPI",
},
]}
/>
NVIDIA OpenShell is the safe, private runtime for autonomous AI agents. It provides sandboxed execution environments
that protect your data, credentials, and infrastructure. Agents run with exactly the permissions they need and
nothing more, governed by declarative policies that prevent unauthorized file access, data exfiltration, and
uncontrolled network activity.
## Get Started
Install OpenShell and create your first sandbox in two commands.
<llms-ignore>
<CommandTerminal command="curl -LsSf https://raw.githubusercontent.com/NVIDIA/OpenShell/main/install.sh | sh" />
</llms-ignore>
<llms-only>
```shell
curl -LsSf https://raw.githubusercontent.com/NVIDIA/OpenShell/main/install.sh | sh
openshell sandbox create -- claude
```
</llms-only>
Refer to the [Quickstart](/get-started/quickstart) for more details.
---
## Explore
<div className="explore-cards">
<Cards>
<Card title="About OpenShell" href="/about/overview">
Learn about OpenShell and its capabilities.
<Badge intent="tip" minimal outlined>Concept</Badge>
</Card>
<Card title="Quickstart" href="/get-started/quickstart">
Install OpenShell and create your first sandbox in two commands.
<Badge intent="tip" minimal outlined>Tutorial</Badge>
</Card>
<Card title="Tutorials" href="/get-started/tutorials">
Hands-on walkthroughs from first sandbox to custom policies.
<Badge intent="tip" minimal outlined>Concept</Badge>
</Card>
<Card title="Gateways and Sandboxes" href="/sandboxes/manage-gateways">
Deploy gateways, create sandboxes, configure policies, providers, and community images for your AI agents.
<Badge intent="tip" minimal outlined>Concept</Badge>
</Card>
<Card title="Provider-backed Inference" href="/sandboxes/inference-routing">
Attach model providers to selected sandboxes and call their native endpoints without exposing credentials.
<Badge intent="tip" minimal outlined>Concept</Badge>
</Card>
<Card title="Observability" href="/observability">
Understand sandbox logs, access them with the CLI and TUI, and export OCSF JSON records.
<Badge intent="tip" minimal outlined>How-To</Badge>
</Card>
<Card title="Reference" href="/reference/default-policy">
Policy schema, environment variables, and default policy details.
<Badge intent="tip" minimal outlined>Reference</Badge>
</Card>
<Card title="Security Best Practices" href="/security/best-practices">
Every configurable security control, its default, and the risk of changing it.
<Badge intent="tip" minimal outlined>Concept</Badge>
</Card>
</Cards>
</div>
---
<Warning title="Notice and Disclaimer">
This software automatically retrieves, accesses or interacts with external
materials. Those retrieved materials are not distributed with this software
and are governed solely by separate terms, conditions and licenses. You are
solely responsible for finding, reviewing and complying with all applicable
terms, conditions, and licenses, and for verifying the security, integrity and
suitability of any retrieved materials for your specific use case. This
software is provided "AS IS", without warranty of any kind. The author makes
no representations or warranties regarding any retrieved materials, and
assumes no liability for any losses, damages, liabilities or legal
consequences from your use or inability to use this software or any retrieved
materials. Use this software and the retrieved materials at your own risk.
</Warning>