mirror of
https://github.com/NVIDIA/OpenShell.git
synced 2026-10-02 07:34:45 +08:00
65 lines
4.3 KiB
Plaintext
65 lines
4.3 KiB
Plaintext
---
|
|
# SPDX-FileCopyrightText: Copyright (c) 2025-2026 NVIDIA CORPORATION & AFFILIATES. All rights reserved.
|
|
# SPDX-License-Identifier: Apache-2.0
|
|
title: "Overview of NVIDIA OpenShell"
|
|
sidebar-title: "Overview"
|
|
description: "OpenShell is the safe, private runtime for fleets of autonomous AI agents. Run agents in sandboxed environments that protect your data, credentials, and infrastructure."
|
|
keywords: "Generative AI, Cybersecurity, AI Agents, Sandboxing, Security, Privacy, Provider Credentials"
|
|
position: 1
|
|
---
|
|
|
|
NVIDIA OpenShell is an open-source runtime for executing fleets of autonomous AI agents in sandboxed environments with kernel-level isolation. It combines sandbox runtime controls and a declarative YAML policy so teams can run agents without giving them unrestricted access to local files, credentials, and external networks.
|
|
|
|
<Note>
|
|
New in OpenShell 0.1.x: a [stable release cadence](/about/support-matrix#releases), new [isolation primitives](/about/architecture), and an expanded [extension surface](/extensibility/overview), along with much more.
|
|
|
|
See our [upgrade guide](/upgrade/0-1-0) for everything that's changed.
|
|
</Note>
|
|
|
|
## Why OpenShell Exists
|
|
|
|
AI agents are most useful when they can read files, install packages, call APIs, and use credentials. That same access can create material risk. OpenShell is designed for this tradeoff: preserve agent capability while enforcing explicit controls over what the agent can access.
|
|
|
|
## Common Risks and Controls
|
|
|
|
The table below summarizes common failure modes and how OpenShell mitigates them.
|
|
|
|
| Threat | Without controls | With OpenShell |
|
|
|---|---|---|
|
|
| Data exfiltration | Agent uploads source code or internal files to unauthorized endpoints. | Network policies allow only approved destinations; other outbound traffic is denied. |
|
|
| Credential theft | Agent reads local secrets such as SSH keys or cloud credentials. | Filesystem restrictions (Landlock) confine access to declared paths only. |
|
|
| Unauthorized API usage | Agent sends prompts or data to unapproved model providers. | Provider profiles and network policies restrict model traffic to approved endpoints and binaries. |
|
|
| Privilege escalation | Agent attempts `sudo`, setuid paths, or dangerous syscall behavior. | Unprivileged process identity and seccomp restrictions block escalation paths. |
|
|
|
|
## Protection Layers at a Glance
|
|
|
|
OpenShell applies defense in depth across the following policy domains.
|
|
|
|
| Layer | What it protects | When it applies |
|
|
|---|---|---|
|
|
| Filesystem | Prevents reads/writes outside allowed paths. | Locked at sandbox creation. |
|
|
| Network | Blocks unauthorized outbound connections. | Hot-reloadable at runtime. |
|
|
| Process | Blocks privilege escalation and dangerous syscalls. | Locked at sandbox creation. |
|
|
| Provider credentials | Resolves opaque credential placeholders only at profile-authorized endpoints. | Attachments, rotation, and revocation update at runtime; new environment variables require a new process. |
|
|
|
|
For details, refer to [Sandbox Policies](/how-it-works/policies/overview) and [Default Policy](/how-it-works/policies/default-policy).
|
|
|
|
## Common Use Cases
|
|
|
|
OpenShell supports a range of agent deployment patterns.
|
|
|
|
| Use Case | Description |
|
|
|-----------------------------|----------------------------------------------------------------------------------------------------------|
|
|
| Secure coding agents | Run Claude Code, OpenCode, Codex, or GitHub Copilot CLI with constrained file and network access. |
|
|
| Private enterprise development | Grant selected sandboxes access to self-hosted or private model endpoints while keeping sensitive context under your control. |
|
|
| Compliance and audit | Treat policy YAML as version-controlled security controls that can be reviewed and audited. |
|
|
| Reusable environments | Use the default Ubuntu workload or bring your own containerized runtime. |
|
|
|
|
## Next Steps
|
|
|
|
Explore these topics to go deeper:
|
|
|
|
- To understand the runtime architecture, refer to [Architecture](/about/architecture).
|
|
- To prepare an image and launch an agent, refer to [Run Your First Agent](/about/run-your-first-agent).
|
|
- To learn how OpenShell enforces policy controls across protection layers, refer to [Sandbox Policies](/how-it-works/policies/overview).
|