mirror of
https://github.com/NVIDIA/OpenShell.git
synced 2026-10-04 08:28:19 +08:00
54 lines
2.7 KiB
Plaintext
54 lines
2.7 KiB
Plaintext
---
|
|
# SPDX-FileCopyrightText: Copyright (c) 2025-2026 NVIDIA CORPORATION & AFFILIATES. All rights reserved.
|
|
# SPDX-License-Identifier: Apache-2.0
|
|
title: "Default Policy Reference"
|
|
sidebar-title: "Default Policy"
|
|
description: "Breakdown of the built-in default policy applied when you create an OpenShell sandbox without a custom policy."
|
|
keywords: "Generative AI, Cybersecurity, AI Agents, Sandboxing, Security, Policy"
|
|
position: 2
|
|
---
|
|
|
|
When you create a sandbox without `--policy`, OpenShell applies a restrictive built-in fallback. The policy comes from the OpenShell runtime and does not depend on the selected workload image.
|
|
|
|
## How an Image Policy Becomes Active
|
|
|
|
If the selected workload image contains a policy, the supervisor offers it to
|
|
the gateway on the first connection. If the gateway already has a policy for
|
|
the sandbox, the gateway policy takes precedence. Otherwise, the gateway uses
|
|
the image policy as the initial candidate. If the image has no policy, the
|
|
gateway uses the built-in fallback.
|
|
|
|
The gateway sends the selected policy back to the supervisor on the same
|
|
connection. The supervisor adds filesystem paths that exist in that image, then
|
|
returns either the unchanged policy or the complete prepared policy. The
|
|
gateway validates and persists the result before it accepts the supervisor
|
|
session. An invalid image or prepared policy prevents sandbox startup.
|
|
|
|
The accepted session contains a fresh gateway-owned configuration bootstrap.
|
|
The supervisor initializes from that bootstrap. It does not initialize from
|
|
the image policy or the preparation response. Reconnects skip image-policy
|
|
preparation and use the current gateway configuration.
|
|
|
|
## Filesystem Access
|
|
|
|
The fallback includes the sandbox working directory and grants read-only access to standard runtime paths:
|
|
|
|
- `/usr`
|
|
- `/lib`
|
|
- `/proc`
|
|
- `/dev/urandom`
|
|
- `/etc`
|
|
- `/var/log`
|
|
|
|
It grants read-write access to `/tmp` and `/dev/null`. Landlock enforcement uses `best_effort` compatibility so OpenShell can use the strongest ABI available on the host while retaining its mandatory baseline protections.
|
|
|
|
## Network Access
|
|
|
|
The fallback defines no network policies or provider-derived endpoints, so outbound network access is denied. Attach a provider or apply a custom policy that names the required endpoints and executable paths before running a networked agent.
|
|
|
|
## Process Identity
|
|
|
|
The fallback leaves process identity selection to the compute driver. Docker and Podman honor a non-root OCI `USER`; when an image declares no user, they use numeric UID and GID `1000`. Kubernetes and MicroVM drivers apply their configured non-root identities.
|
|
|
|
Use `openshell policy get <sandbox> --full` to inspect the effective policy. Refer to [Customize Sandbox Policies](/sandboxes/policies) to replace the fallback.
|