mirror of
https://github.com/NVIDIA/OpenShell.git
synced 2026-10-02 07:34:45 +08:00
* refactor(config): normalize compute driver field names Signed-off-by: Jesse Jaggars <jjaggars@redhat.com> * refactor(config): introduce canonical gateway fields Signed-off-by: Jesse Jaggars <jjaggars@redhat.com> * refactor(config): enforce gateway schema version 2 Signed-off-by: Jesse Jaggars <jjaggars@redhat.com> * fix(config): preserve compute driver runtime guarantees Signed-off-by: Jesse Jaggars <jjaggars@redhat.com> * fix(config): address schema v2 review regressions Signed-off-by: Jesse Jaggars <jjaggars@redhat.com> * fix(config): complete schema v2 migration safeguards Signed-off-by: Jesse Jaggars <jjaggars@redhat.com> * test(config): expand schema v2 regression coverage Signed-off-by: Jesse Jaggars <jjaggars@redhat.com> * test(config): add schema v2 parity manifest Signed-off-by: Jesse Jaggars <jjaggars@redhat.com> * fix(config): correct parity manifest inventory Signed-off-by: Jesse Jaggars <jjaggars@redhat.com> * docs(config): record schema v2 intentional changes Signed-off-by: Jesse Jaggars <jjaggars@redhat.com> * docs(config): disposition schema v2 parity gaps Signed-off-by: Jesse Jaggars <jjaggars@redhat.com> * test(e2e): add dual schema parity harness Signed-off-by: Jesse Jaggars <jjaggars@redhat.com> * test(e2e): establish compute lifecycle parity baseline Signed-off-by: Jesse Jaggars <jjaggars@redhat.com> * fix(config): preserve gateway option compatibility Signed-off-by: Jesse Jaggars <jjaggars@redhat.com> * test(e2e): record gateway option parity Signed-off-by: Jesse Jaggars <jjaggars@redhat.com> * docs(config): close gateway-wide parity gaps Signed-off-by: Jesse Jaggars <jjaggars@redhat.com> * fix(podman): apply configured pids limit Signed-off-by: Jesse Jaggars <jjaggars@redhat.com> * test(e2e): validate Podman option parity Signed-off-by: Jesse Jaggars <jjaggars@redhat.com> * test(e2e): add Kubernetes option parity harness Signed-off-by: Jesse Jaggars <jjaggars@redhat.com> * test(e2e): record Kubernetes option parity Signed-off-by: Jesse Jaggars <jjaggars@redhat.com> * test(e2e): disposition VM parity lanes Signed-off-by: Jesse Jaggars <jjaggars@redhat.com> * test(e2e): add external driver parity lane Signed-off-by: Jesse Jaggars <jjaggars@redhat.com> * fix(e2e): preserve external driver pull policy Signed-off-by: Jesse Jaggars <jjaggars@redhat.com> * test(e2e): attest parity artifacts and launches Signed-off-by: Jesse Jaggars <jjaggars@redhat.com> * test(e2e): require clean parity build sources Signed-off-by: Jesse Jaggars <jjaggars@redhat.com> * test(e2e): bind parity runtime artifacts Signed-off-by: Jesse Jaggars <jjaggars@redhat.com> * fix(e2e): use isolated supervisor tags Signed-off-by: Jesse Jaggars <jjaggars@redhat.com> * fix(e2e): qualify parity image tags Signed-off-by: Jesse Jaggars <jjaggars@redhat.com> * fix(e2e): serve parity supervisor locally Signed-off-by: Jesse Jaggars <jjaggars@redhat.com> * test(e2e): isolate parity podman services Signed-off-by: Jesse Jaggars <jjaggars@redhat.com> * test(e2e): harden parity evidence provenance Signed-off-by: Jesse Jaggars <jjaggars@redhat.com> * test(e2e): pin parity sandbox artifacts Signed-off-by: Jesse Jaggars <jjaggars@redhat.com> * test(e2e): attest parity runtime inputs Signed-off-by: Jesse Jaggars <jjaggars@redhat.com> * test(e2e): bind parity runtime evidence Signed-off-by: Jesse Jaggars <jjaggars@redhat.com> * test(e2e): record compute boundary parity Signed-off-by: Jesse Jaggars <jjaggars@redhat.com> * test(e2e): disposition cross-cutting parity lanes Signed-off-by: Jesse Jaggars <jjaggars@redhat.com> * fix(packaging): preflight gateway config upgrades Signed-off-by: Jesse Jaggars <jjaggars@redhat.com> * fix(config): preserve rebase integration guarantees Signed-off-by: Jesse Jaggars <jjaggars@redhat.com> * test(ci): isolate temporary git signing config Signed-off-by: Jesse Jaggars <jjaggars@redhat.com> * fix(config): update remaining schema v2 consumers Signed-off-by: Jesse Jaggars <jjaggars@redhat.com> * fix(ci): provide e2fs tools to VM tests Signed-off-by: Jesse Jaggars <jjaggars@redhat.com> * fix(config): align preflight with gateway startup Signed-off-by: Jesse Jaggars <jjaggars@redhat.com> * fix(vm): preserve rootfs tar configuration Signed-off-by: Jesse Jaggars <jjaggars@redhat.com> * chore(config): adopt duration unit constructors Signed-off-by: Jesse Jaggars <jjaggars@redhat.com> * fix(packaging): preflight RPM gateway config Signed-off-by: Jesse Jaggars <jjaggars@redhat.com> * fix(config): address driver review findings Signed-off-by: Jesse Jaggars <jjaggars@redhat.com> * fix(e2e): require fresh semantic parity evidence Signed-off-by: Jesse Jaggars <jjaggars@redhat.com> * fix(docker): update tests for renamed sandbox label Signed-off-by: Jesse Jaggars <jjaggars@redhat.com> * test(gateway): preserve selective driver coverage after rebase Signed-off-by: Drew Newberry <anewberry@nvidia.com> --------- Signed-off-by: Jesse Jaggars <jjaggars@redhat.com> Signed-off-by: Drew Newberry <anewberry@nvidia.com> Co-authored-by: Drew Newberry <anewberry@nvidia.com>
159 lines
5.4 KiB
YAML
159 lines
5.4 KiB
YAML
# SPDX-FileCopyrightText: Copyright (c) 2025-2026 NVIDIA CORPORATION & AFFILIATES. All rights reserved.
|
|
# SPDX-License-Identifier: Apache-2.0
|
|
|
|
name: openshell
|
|
title: OpenShell
|
|
adopt-info: openshell
|
|
summary: Safe, sandboxed runtimes for autonomous AI agents
|
|
description: |
|
|
OpenShell provides safe, sandboxed runtimes for autonomous AI agents.
|
|
It offers a CLI for managing gateways, sandboxes, and providers with
|
|
policy-enforced egress routing, credential proxying, and privacy-aware
|
|
profile-backed model-provider access.
|
|
|
|
The OpenShell snap ships a CLI (`openshell`), a terminal UI
|
|
(`openshell.term`), and a managed gateway daemon (`openshell.gateway`).
|
|
|
|
**Setup instructions**
|
|
|
|
1. Install the Docker snap:
|
|
|
|
sudo snap install docker
|
|
|
|
Support for system-installed Docker is coming in snapd 2.76.
|
|
|
|
2. Connect the required interfaces:
|
|
|
|
sudo snap connect openshell:docker docker:docker-daemon
|
|
sudo snap connect openshell:log-observe
|
|
sudo snap connect openshell:system-observe
|
|
|
|
3. Verify the gateway and register it locally:
|
|
|
|
snap services openshell.gateway
|
|
openshell status
|
|
openshell gateway add http://127.0.0.1:17670 --local --name openshell-gateway
|
|
|
|
After a snap refresh, restart the gateway to pick up the new revision:
|
|
|
|
sudo snap restart openshell.gateway
|
|
|
|
Restarting the gateway will interrupt active sandbox sessions. The gateway
|
|
is not restarted automatically to avoid disconnecting running sandboxes.
|
|
|
|
base: core24
|
|
grade: stable
|
|
confinement: strict
|
|
license: Apache-2.0
|
|
website: https://docs.nvidia.com/openshell/latest/index.html
|
|
source-code: https://github.com/NVIDIA/OpenShell
|
|
issues: https://github.com/NVIDIA/OpenShell/issues
|
|
contact: https://github.com/NVIDIA/OpenShell/security/policy
|
|
platforms:
|
|
amd64:
|
|
build-on: [amd64]
|
|
build-for: [amd64]
|
|
arm64:
|
|
build-on: [arm64]
|
|
build-for: [arm64]
|
|
|
|
apps:
|
|
openshell:
|
|
command: bin/openshell
|
|
environment:
|
|
XDG_CONFIG_HOME: "$SNAP_USER_COMMON/.config"
|
|
XDG_DATA_HOME: "$SNAP_USER_COMMON/.local/share"
|
|
XDG_STATE_HOME: "$SNAP_USER_COMMON/.local/state"
|
|
plugs:
|
|
- home
|
|
- network
|
|
- system-observe
|
|
term:
|
|
command: bin/openshell term
|
|
desktop: meta/gui/term.desktop
|
|
environment:
|
|
XDG_CONFIG_HOME: "$SNAP_USER_COMMON/.config"
|
|
XDG_DATA_HOME: "$SNAP_USER_COMMON/.local/share"
|
|
XDG_STATE_HOME: "$SNAP_USER_COMMON/.local/state"
|
|
plugs:
|
|
- home
|
|
- network
|
|
- system-observe
|
|
gateway:
|
|
command: bin/openshell-gateway-wrapper
|
|
daemon: simple
|
|
# refresh-mode: endure prevents snapd from restarting the gateway daemon
|
|
# during snap refreshes, which would kill active sandbox sessions.
|
|
# Operators must manually restart the service after a refresh if needed.
|
|
refresh-mode: endure
|
|
# The wrapper sets OPENSHELL_DISABLE_TLS=true and OPENSHELL_DB_URL to
|
|
# use $SNAP_COMMON/gateway.db. Before startup it validates the selected
|
|
# operator-provided config without creating or rewriting it. A nonempty
|
|
# OPENSHELL_GATEWAY_CONFIG takes precedence over gateway.toml.
|
|
environment:
|
|
XDG_DATA_HOME: "$SNAP_COMMON"
|
|
XDG_RUNTIME_DIR: "$SNAP_COMMON"
|
|
plugs:
|
|
- docker
|
|
# Docker snap is required because the snap uses the docker:docker-daemon
|
|
# interface slot. It does not work with system-installed Docker.
|
|
- log-observe
|
|
- network
|
|
- network-bind
|
|
- system-observe
|
|
|
|
parts:
|
|
openshell:
|
|
plugin: nil
|
|
source: ./snap/prebuilt
|
|
override-pull: |
|
|
craftctl default
|
|
craftctl set version="$(cat "$CRAFT_PART_SRC/version")"
|
|
override-build: |
|
|
set -euo pipefail
|
|
|
|
MISSING=()
|
|
for bin in openshell openshell-gateway openshell-sandbox openshell-gateway-wrapper; do
|
|
if [ ! -f "$CRAFT_PART_SRC/$bin" ]; then
|
|
MISSING+=("$bin")
|
|
fi
|
|
done
|
|
|
|
if [ ${#MISSING[@]} -gt 0 ]; then
|
|
printf '%s\n' \
|
|
"ERROR: snap/prebuilt/ is incomplete:" \
|
|
"${MISSING[@]/#/' - '}" \
|
|
"" \
|
|
"The snap build directory must be populated by CI before snapcraft pack." \
|
|
>&2
|
|
exit 1
|
|
fi
|
|
|
|
install -D -m 0755 "$CRAFT_PART_SRC/openshell" \
|
|
"$CRAFT_PART_INSTALL/bin/openshell"
|
|
install -D -m 0755 "$CRAFT_PART_SRC/openshell-gateway" \
|
|
"$CRAFT_PART_INSTALL/bin/openshell-gateway"
|
|
install -D -m 0755 "$CRAFT_PART_SRC/openshell-sandbox" \
|
|
"$CRAFT_PART_INSTALL/bin/openshell-sandbox"
|
|
install -D -m 0755 "$CRAFT_PART_SRC/openshell-gateway-wrapper" \
|
|
"$CRAFT_PART_INSTALL/bin/openshell-gateway-wrapper"
|
|
install -D -m 0644 "$CRAFT_PART_SRC/meta/gui/term.desktop" \
|
|
"$CRAFT_PART_INSTALL/meta/gui/term.desktop"
|
|
install -D -m 0644 "$CRAFT_PART_SRC/meta/gui/icon.png" \
|
|
"$CRAFT_PART_INSTALL/meta/gui/icon.png"
|
|
install -D -m 0644 "$CRAFT_PART_SRC/LICENSE" \
|
|
"$CRAFT_PART_INSTALL/usr/share/doc/openshell/LICENSE"
|
|
install -D -m 0644 "$CRAFT_PART_SRC/README.md" \
|
|
"$CRAFT_PART_INSTALL/usr/share/doc/openshell/README.md"
|
|
|
|
ssh:
|
|
# Vendor the openssh-client `ssh` binary into the snap so the CLI/TUI
|
|
# can spawn `ssh` for sandbox connect/exec/forward without relying on
|
|
# the host's ssh-keys interface. The binary lands at
|
|
# $SNAP/usr/bin/ssh and is found via the snap runtime PATH.
|
|
plugin: nil
|
|
stage-packages:
|
|
- openssh-client
|
|
prime:
|
|
- usr/bin/ssh
|