mirror of
https://github.com/NVIDIA/OpenShell.git
synced 2026-10-02 07:34:45 +08:00
* docs: refresh architecture and agent guides Signed-off-by: Drew Newberry <anewberry@nvidia.com> * docs: describe updated security architecture neutrally Signed-off-by: Drew Newberry <anewberry@nvidia.com> * docs: highlight new isolation primitives Signed-off-by: Drew Newberry <anewberry@nvidia.com> * docs(sandboxes): clarify how to disconnect Signed-off-by: Drew Newberry <anewberry@nvidia.com> * docs: align architecture and guides with current navigation Signed-off-by: Drew Newberry <anewberry@nvidia.com> * docs(extensibility): streamline extension authentication guidance Signed-off-by: Drew Newberry <anewberry@nvidia.com> --------- Signed-off-by: Drew Newberry <anewberry@nvidia.com>
61 lines
3.2 KiB
Plaintext
61 lines
3.2 KiB
Plaintext
---
|
|
# SPDX-FileCopyrightText: Copyright (c) 2026 NVIDIA CORPORATION & AFFILIATES. All rights reserved.
|
|
# SPDX-License-Identifier: Apache-2.0
|
|
title: "Drivers"
|
|
description: "Understand the compute and credential driver extension points in OpenShell."
|
|
keywords: "OpenShell Extensions, Compute Drivers, Credential Drivers, Extensibility"
|
|
---
|
|
|
|
OpenShell uses drivers to connect the gateway to workload runtimes and
|
|
credential stores. Drivers implement a stable capability boundary while the
|
|
gateway owns the public API, authorization, workspace scoping, and resource
|
|
lifecycle.
|
|
|
|
## Compute Drivers
|
|
|
|
Compute drivers create, inspect, and delete sandbox workloads. OpenShell ships
|
|
drivers for Kubernetes, Docker, Podman, virtual machines, and Windows MXC. An
|
|
external compute driver communicates with the gateway over a Unix domain
|
|
socket and negotiates its protocol version and capabilities before serving
|
|
requests.
|
|
|
|
For built-in driver configuration and behavior, refer to
|
|
[Runtimes](/how-it-works/sandboxes/runtimes). For implementation details, refer
|
|
to each driver crate:
|
|
|
|
| Driver | Crate |
|
|
|---|---|
|
|
| Docker | [`openshell-driver-docker`](https://github.com/NVIDIA/OpenShell/blob/main/crates/openshell-driver-docker/README.md) |
|
|
| Podman | [`openshell-driver-podman`](https://github.com/NVIDIA/OpenShell/blob/main/crates/openshell-driver-podman/README.md) |
|
|
| MicroVM | [`openshell-driver-vm`](https://github.com/NVIDIA/OpenShell/blob/main/crates/openshell-driver-vm/README.md) |
|
|
| Kubernetes | [`openshell-driver-kubernetes`](https://github.com/NVIDIA/OpenShell/blob/main/crates/openshell-driver-kubernetes/README.md) |
|
|
| Windows MXC | [`openshell-driver-mxc`](https://github.com/NVIDIA/OpenShell/blob/main/crates/openshell-driver-mxc/README.md) |
|
|
|
|
External compute drivers implement [`compute_driver.proto`](https://github.com/NVIDIA/OpenShell/blob/main/proto/compute_driver.proto).
|
|
|
|
## Credential Drivers
|
|
|
|
Credential drivers store provider credentials behind opaque handles. The
|
|
gateway resolves those handles when a provider is attached without persisting
|
|
the secret value in the provider record. OpenShell includes database,
|
|
Kubernetes Secret, and Vault-compatible credential drivers.
|
|
|
|
Configure the active credential driver in the
|
|
[Gateway Configuration](/how-it-works/gateways/configuration#credential-drivers).
|
|
For implementation details, refer to each driver crate:
|
|
|
|
| Driver | Crate |
|
|
|---|---|
|
|
| Database | [`openshell-driver-db-credstore`](https://github.com/NVIDIA/OpenShell/tree/main/crates/openshell-driver-db-credstore) |
|
|
| Kubernetes Secrets | [`openshell-driver-kubernetes-secrets`](https://github.com/NVIDIA/OpenShell/tree/main/crates/openshell-driver-kubernetes-secrets) |
|
|
| Vault | [`openshell-driver-vault`](https://github.com/NVIDIA/OpenShell/tree/main/crates/openshell-driver-vault) |
|
|
|
|
External credential drivers implement [`credential_driver.proto`](https://github.com/NVIDIA/OpenShell/blob/main/proto/credential_driver.proto).
|
|
|
|
## Compatibility
|
|
|
|
Drivers exchange peer metadata with the gateway and advertise their extension
|
|
family capability. Upgrade both peers together when the protocol version
|
|
changes. Refer to [Extension Protocol Negotiation](/extensibility/overview#protocol-negotiation)
|
|
for the negotiation contract.
|