Files
OpenShell/snapcraft.yaml
Drew Newberry 17ce738bfb fix(ci)!: remove gateway callback listener dependency (#3365)
* fix(ci): repair post-merge release canary

Signed-off-by: Drew Newberry <anewberry@nvidia.com>

* fix(packaging): bootstrap canary runtime prerequisites

Signed-off-by: Drew Newberry <anewberry@nvidia.com>

* ci(canary): collect macOS VM diagnostics

Signed-off-by: Drew Newberry <anewberry@nvidia.com>

* ci(canary): pin libkrun-compatible macOS runner

Signed-off-by: Drew Newberry <anewberry@nvidia.com>

* ci(canary): limit macOS smoke test to package startup

Signed-off-by: Drew Newberry <anewberry@nvidia.com>

* refactor(compute)!: remove gateway callback listeners

Run Docker supervisors on host networking so they use the operator-configured primary gateway endpoint. Remove the unused compute-driver callback listener negotiation and listener-scoped routing machinery.

BREAKING CHANGE: The ComputeDriver API no longer exposes GetGatewayListenerRequirements or GatewayListenerRequirement. External drivers must regenerate bindings and connect supervisors to the configured primary gateway endpoint.

Signed-off-by: Drew Newberry <anewberry@nvidia.com>

* refactor(docker): use sandbox runtime image in launcher

Signed-off-by: Drew Newberry <anewberry@nvidia.com>

* test(podman): exercise production endpoint selection

Signed-off-by: Drew Newberry <anewberry@nvidia.com>

* fix(e2e): route supervisors to reachable gateways

Signed-off-by: Drew Newberry <anewberry@nvidia.com>

* test(e2e): align Podman endpoint fixtures

Signed-off-by: Drew Newberry <anewberry@nvidia.com>

* fix(docker): preserve host aliases for supervisors

Signed-off-by: Drew Newberry <anewberry@nvidia.com>

* fix(docker): align sandbox host gateway pin

Signed-off-by: Drew Newberry <anewberry@nvidia.com>

* fix(e2e): address Docker fixtures by bridge IP

Signed-off-by: Drew Newberry <anewberry@nvidia.com>

* test(e2e): serialize sandbox lifecycle cases

Signed-off-by: Drew Newberry <anewberry@nvidia.com>

* fix(e2e): host Docker TCP fixture with gateway

Signed-off-by: Drew Newberry <anewberry@nvidia.com>

* fix(e2e): use loopback for host-network supervisor

Signed-off-by: Drew Newberry <anewberry@nvidia.com>

---------

Signed-off-by: Drew Newberry <anewberry@nvidia.com>
2026-09-18 20:55:55 +00:00

160 lines
5.4 KiB
YAML

# SPDX-FileCopyrightText: Copyright (c) 2025-2026 NVIDIA CORPORATION & AFFILIATES. All rights reserved.
# SPDX-License-Identifier: Apache-2.0
name: openshell
title: OpenShell
adopt-info: openshell
summary: Safe, sandboxed runtimes for autonomous AI agents
description: |
OpenShell provides safe, sandboxed runtimes for autonomous AI agents.
It offers a CLI for managing gateways, sandboxes, and providers with
policy-enforced egress routing, credential proxying, and privacy-aware
profile-backed model-provider access.
The OpenShell snap ships a CLI (`openshell`), a terminal UI
(`openshell.term`), and a managed gateway daemon (`openshell.gateway`).
**Setup instructions**
1. Install the Docker snap:
sudo snap install docker
Support for system-installed Docker is coming in snapd 2.76.
2. Connect the required interfaces:
sudo snap connect openshell:docker docker:docker-daemon
sudo snap connect openshell:log-observe
sudo snap connect openshell:system-observe
3. Verify the gateway and register it locally:
snap services openshell.gateway
openshell status
openshell gateway add http://127.0.0.1:17670 --local --name openshell-gateway
After a snap refresh, restart the gateway to pick up the new revision:
sudo snap restart openshell.gateway
Restarting the gateway will interrupt active sandbox sessions. The gateway
is not restarted automatically to avoid disconnecting running sandboxes.
base: core24
grade: stable
confinement: strict
license: Apache-2.0
website: https://docs.nvidia.com/openshell/latest/index.html
source-code: https://github.com/NVIDIA/OpenShell
issues: https://github.com/NVIDIA/OpenShell/issues
contact: https://github.com/NVIDIA/OpenShell/security/policy
platforms:
amd64:
build-on: [amd64]
build-for: [amd64]
arm64:
build-on: [arm64]
build-for: [arm64]
apps:
openshell:
command: bin/openshell
environment:
XDG_CONFIG_HOME: "$SNAP_USER_COMMON/.config"
XDG_DATA_HOME: "$SNAP_USER_COMMON/.local/share"
XDG_STATE_HOME: "$SNAP_USER_COMMON/.local/state"
plugs:
- home
- network
- system-observe
term:
command: bin/openshell term
desktop: meta/gui/term.desktop
environment:
XDG_CONFIG_HOME: "$SNAP_USER_COMMON/.config"
XDG_DATA_HOME: "$SNAP_USER_COMMON/.local/share"
XDG_STATE_HOME: "$SNAP_USER_COMMON/.local/state"
plugs:
- home
- network
- system-observe
gateway:
command: bin/openshell-gateway-wrapper
daemon: simple
# refresh-mode: endure prevents snapd from restarting the gateway daemon
# during snap refreshes, which would kill active sandbox sessions.
# Operators must manually restart the service after a refresh if needed.
refresh-mode: endure
# The wrapper sets OPENSHELL_DISABLE_TLS=true and OPENSHELL_DB_URL to
# use $SNAP_COMMON/gateway.db. Before startup it bootstraps package-managed
# credentials and validates the selected operator-provided config without
# creating or rewriting it. A nonempty OPENSHELL_GATEWAY_CONFIG takes
# precedence over gateway.toml.
environment:
XDG_DATA_HOME: "$SNAP_COMMON"
XDG_RUNTIME_DIR: "$SNAP_COMMON"
plugs:
- docker
# Docker snap is required because the snap uses the docker:docker-daemon
# interface slot. It does not work with system-installed Docker.
- log-observe
- network
- network-bind
- system-observe
parts:
openshell:
plugin: nil
source: ./snap/prebuilt
override-pull: |
craftctl default
craftctl set version="$(cat "$CRAFT_PART_SRC/version")"
override-build: |
set -euo pipefail
MISSING=()
for bin in openshell openshell-gateway openshell-sandbox openshell-gateway-wrapper; do
if [ ! -f "$CRAFT_PART_SRC/$bin" ]; then
MISSING+=("$bin")
fi
done
if [ ${#MISSING[@]} -gt 0 ]; then
printf '%s\n' \
"ERROR: snap/prebuilt/ is incomplete:" \
"${MISSING[@]/#/' - '}" \
"" \
"The snap build directory must be populated by CI before snapcraft pack." \
>&2
exit 1
fi
install -D -m 0755 "$CRAFT_PART_SRC/openshell" \
"$CRAFT_PART_INSTALL/bin/openshell"
install -D -m 0755 "$CRAFT_PART_SRC/openshell-gateway" \
"$CRAFT_PART_INSTALL/bin/openshell-gateway"
install -D -m 0755 "$CRAFT_PART_SRC/openshell-sandbox" \
"$CRAFT_PART_INSTALL/bin/openshell-sandbox"
install -D -m 0755 "$CRAFT_PART_SRC/openshell-gateway-wrapper" \
"$CRAFT_PART_INSTALL/bin/openshell-gateway-wrapper"
install -D -m 0644 "$CRAFT_PART_SRC/meta/gui/term.desktop" \
"$CRAFT_PART_INSTALL/meta/gui/term.desktop"
install -D -m 0644 "$CRAFT_PART_SRC/meta/gui/icon.png" \
"$CRAFT_PART_INSTALL/meta/gui/icon.png"
install -D -m 0644 "$CRAFT_PART_SRC/LICENSE" \
"$CRAFT_PART_INSTALL/usr/share/doc/openshell/LICENSE"
install -D -m 0644 "$CRAFT_PART_SRC/README.md" \
"$CRAFT_PART_INSTALL/usr/share/doc/openshell/README.md"
ssh:
# Vendor the openssh-client `ssh` binary into the snap so the CLI/TUI
# can spawn `ssh` for sandbox connect/exec/forward without relying on
# the host's ssh-keys interface. The binary lands at
# $SNAP/usr/bin/ssh and is found via the snap runtime PATH.
plugin: nil
stage-packages:
- openssh-client
prime:
- usr/bin/ssh