mirror of
https://github.com/NVIDIA/OpenShell.git
synced 2026-10-02 07:34:45 +08:00
147 lines
4.8 KiB
Plaintext
147 lines
4.8 KiB
Plaintext
---
|
|
# SPDX-FileCopyrightText: Copyright (c) 2025-2026 NVIDIA CORPORATION & AFFILIATES. All rights reserved.
|
|
# SPDX-License-Identifier: Apache-2.0
|
|
title: "NVIDIA OpenShell Developer Guide"
|
|
description: "OpenShell is the safe, private runtime for fleets of autonomous AI agents. Run agents in sandboxed environments that protect your data, credentials, and infrastructure."
|
|
keywords: "Generative AI, Cybersecurity, AI Agents, Sandboxing, Security, Privacy, Provider Credentials"
|
|
position: 1
|
|
---
|
|
|
|
import { BadgeLinks } from "./_components/BadgeLinks";
|
|
import { CommandTerminal } from "./_components/CommandTerminal";
|
|
|
|
<BadgeLinks
|
|
badges={[
|
|
{
|
|
href: "https://github.com/NVIDIA/OpenShell",
|
|
src: "https://img.shields.io/badge/github-repo-green?logo=github",
|
|
alt: "GitHub",
|
|
},
|
|
{
|
|
href: "https://github.com/NVIDIA/OpenShell/blob/main/LICENSE",
|
|
src: "https://img.shields.io/badge/License-Apache_2.0-blue",
|
|
alt: "License",
|
|
},
|
|
{
|
|
href: "https://pypi.org/project/openshell/",
|
|
src: "https://img.shields.io/badge/PyPI-openshell-orange?logo=pypi",
|
|
alt: "PyPI",
|
|
},
|
|
]}
|
|
/>
|
|
|
|
NVIDIA OpenShell is the safe, private runtime for fleets of autonomous AI agents. It provides sandboxed execution environments
|
|
that protect your data, credentials, and infrastructure. Agents run with exactly the permissions they need and
|
|
nothing more, governed by declarative policies that prevent unauthorized file access, data exfiltration, and
|
|
uncontrolled network activity.
|
|
|
|
<Note>
|
|
New in OpenShell 0.1.x: a [stable release cadence](/about/support-matrix#releases), new [isolation primitives](/about/architecture), and an expanded [extension surface](/extensibility/overview), along with much more.
|
|
|
|
See our [upgrade guide](/upgrade/0-1-0) for everything that's changed.
|
|
</Note>
|
|
|
|
## Get Started
|
|
|
|
Install OpenShell and create your first sandbox in two commands.
|
|
|
|
<llms-ignore>
|
|
|
|
<CommandTerminal command="curl -LsSf https://raw.githubusercontent.com/NVIDIA/OpenShell/main/install.sh | sh" />
|
|
|
|
</llms-ignore>
|
|
|
|
<llms-only>
|
|
|
|
```shell
|
|
curl -LsSf https://raw.githubusercontent.com/NVIDIA/OpenShell/main/install.sh | sh
|
|
openshell sandbox create
|
|
```
|
|
|
|
</llms-only>
|
|
|
|
Refer to [Run Your First Agent](/about/run-your-first-agent) for the complete image,
|
|
provider, and policy workflow.
|
|
|
|
---
|
|
|
|
## Explore
|
|
|
|
<div className="explore-cards">
|
|
<Cards>
|
|
|
|
<Card title="About OpenShell" href="/about/overview">
|
|
|
|
Learn about OpenShell and its capabilities.
|
|
|
|
<Badge intent="tip" minimal outlined>Concept</Badge>
|
|
</Card>
|
|
|
|
<Card title="Run Your First Agent" href="/about/run-your-first-agent">
|
|
|
|
Prepare an image, attach providers, and launch an agent in a sandbox.
|
|
|
|
<Badge intent="tip" minimal outlined>Tutorial</Badge>
|
|
</Card>
|
|
|
|
<Card title="Tutorials" href="/tutorials">
|
|
|
|
Hands-on walkthroughs from first sandbox to custom policies.
|
|
|
|
<Badge intent="tip" minimal outlined>Concept</Badge>
|
|
</Card>
|
|
|
|
<Card title="Gateways and Sandboxes" href="/how-it-works/gateways/overview">
|
|
|
|
Deploy gateways, create sandboxes, configure policies, providers, and workload images for your AI agents.
|
|
|
|
<Badge intent="tip" minimal outlined>Concept</Badge>
|
|
</Card>
|
|
|
|
<Card title="Inference" href="/how-it-works/inference">
|
|
|
|
Attach model providers to selected sandboxes and call their native endpoints without exposing credentials.
|
|
|
|
<Badge intent="tip" minimal outlined>Concept</Badge>
|
|
</Card>
|
|
|
|
<Card title="Observability" href="/observability">
|
|
|
|
Understand sandbox logs, access them with the CLI and TUI, and export OCSF JSON records.
|
|
|
|
<Badge intent="tip" minimal outlined>How-To</Badge>
|
|
</Card>
|
|
|
|
<Card title="Policies" href="/how-it-works/policies/overview">
|
|
|
|
Define filesystem, process, and network controls for sandbox workloads.
|
|
|
|
<Badge intent="tip" minimal outlined>Reference</Badge>
|
|
</Card>
|
|
|
|
<Card title="Security Best Practices" href="/security/best-practices">
|
|
|
|
Every configurable security control, its default, and the risk of changing it.
|
|
|
|
<Badge intent="tip" minimal outlined>Concept</Badge>
|
|
</Card>
|
|
|
|
</Cards>
|
|
</div>
|
|
|
|
---
|
|
|
|
<Warning title="Notice and Disclaimer">
|
|
This software automatically retrieves, accesses or interacts with external
|
|
materials. Those retrieved materials are not distributed with this software
|
|
and are governed solely by separate terms, conditions and licenses. You are
|
|
solely responsible for finding, reviewing and complying with all applicable
|
|
terms, conditions, and licenses, and for verifying the security, integrity and
|
|
suitability of any retrieved materials for your specific use case. This
|
|
software is provided "AS IS", without warranty of any kind. The author makes
|
|
no representations or warranties regarding any retrieved materials, and
|
|
assumes no liability for any losses, damages, liabilities or legal
|
|
consequences from your use or inability to use this software or any retrieved
|
|
materials. Use this software and the retrieved materials at your own risk.
|
|
</Warning>
|