Skip to content

Commit dc565bf

Browse files
committed
docs: align navigation and 0.1.0 guidance
Signed-off-by: Drew Newberry <anewberry@nvidia.com>
1 parent c5285bf commit dc565bf

27 files changed

Lines changed: 197 additions & 516 deletions

‎README.md‎

Lines changed: 7 additions & 14 deletions
Original file line numberDiff line numberDiff line change
@@ -15,13 +15,13 @@
1515
[![Project Status](https://img.shields.io/badge/status-alpha-orange)](https://github.com/NVIDIA/OpenShell/releases)
1616

1717
> [!IMPORTANT]
18-
> **OpenShell 0.1.0 is coming soon.** [Track progress in the 0.1.0 milestone](https://github.com/NVIDIA/OpenShell/milestone/10), [read the prerelease documentation](https://docs.nvidia.com/openshell/dev/index.html), or [install a prerelease](#prerelease-and-development-builds).
18+
> **New in OpenShell 0.1.0:** a stable release cadence, an improved security model, an expanded extension surface, and new APIs. [Read the 0.1.0 upgrade guide](https://docs.nvidia.com/openshell/latest/upgrade/0-1-0).
1919
2020
OpenShell is the safe, private runtime for autonomous AI agents. It provides sandboxed execution environments that protect your data, credentials, and infrastructure — governed by declarative YAML policies that prevent unauthorized file access, data exfiltration, and uncontrolled network activity.
2121

2222
OpenShell is built agent-first. It ships public agent skills for using and operating OpenShell, plus separate repository-aware workflows for contributors and maintainers.
2323

24-
## Quickstart
24+
## Install OpenShell
2525

2626
### Prerequisites
2727

@@ -190,20 +190,13 @@ Docker-backed GPU sandboxes auto-select CDI when available and otherwise fall ba
190190

191191
**Requirements:** NVIDIA drivers and the [NVIDIA Container Toolkit](https://docs.nvidia.com/datacenter/cloud-native/container-toolkit/latest/install-guide.html) must be installed on the host. The sandbox image itself must include the appropriate GPU drivers and libraries for your workload — the default Ubuntu image does not. See the [BYOC example](https://github.com/NVIDIA/OpenShell/tree/main/examples/bring-your-own-container) for building a custom sandbox image with GPU support.
192192

193-
## Supported Agents
193+
## Running Agents
194194

195195
OpenShell can run Linux agents packaged in OCI images. The default Ubuntu
196196
workload does not bundle agent CLIs. Build or select an image containing your
197-
agent, then authorize its binary paths, service endpoints, and credentials.
198-
199-
| Agent | Integration |
200-
| ----- | ----------- |
201-
| [Claude Code](https://docs.anthropic.com/en/docs/claude-code) | Package Claude Code in a workload image and attach a `claude-code` provider or another endpoint-bearing model profile. |
202-
| [OpenCode](https://opencode.ai/) | Package OpenCode in a workload image and attach its model provider and policy. |
203-
| [Codex](https://developers.openai.com/codex) | Package Codex in a workload image and attach an OpenAI provider and policy. |
204-
| [GitHub Copilot CLI](https://docs.github.com/en/copilot/github-copilot-in-the-cli) | Package the CLI in a workload image and attach GitHub credentials and policy. |
205-
| [OpenClaw](https://openclaw.ai/) | Use the [NemoClaw](https://github.com/NVIDIA/NemoClaw) blueprint. |
206-
| [Hermes Agent](https://github.com/NousResearch/hermes-agent) | Use the [NemoClaw](https://github.com/NVIDIA/NemoClaw) blueprint. |
197+
agent, then authorize its binary paths, service endpoints, and credentials. See
198+
[Run Your First Agent](https://docs.nvidia.com/openshell/latest/about/run-an-agent)
199+
for the image, provider, and policy workflow.
207200

208201
## Key Commands
209202

@@ -284,7 +277,7 @@ Agent implementation is human-directed: a user may request a phase directly, or
284277
## Learn More
285278

286279
- [Full Documentation](https://docs.nvidia.com/openshell/latest/index.html) — overview, architecture, tutorials, and reference
287-
- [Quickstart](https://docs.nvidia.com/openshell/latest/get-started/quickstart) — detailed install and first sandbox walkthrough
280+
- [Run Your First Agent](https://docs.nvidia.com/openshell/latest/about/run-an-agent) — prepare an image, attach providers, and launch an agent
288281
- [GitHub Sandbox Tutorial](https://docs.nvidia.com/openshell/latest/get-started/tutorials/github-sandbox) — end-to-end scoped GitHub repo access
289282
- [Architecture](https://github.com/NVIDIA/OpenShell/tree/main/architecture) — detailed architecture docs and design decisions
290283
- [Roadmap](https://github.com/orgs/NVIDIA/projects/233) — planned work and project priorities

‎docs/_components/CommandTerminal.tsx‎

Lines changed: 1 addition & 67 deletions
Original file line numberDiff line numberDiff line change
@@ -3,10 +3,6 @@
33
* SPDX-License-Identifier: Apache-2.0
44
*/
55

6-
declare const React: unknown;
7-
8-
const rotatingAgents = ["", "claude", "opencode", "codex"];
9-
106
export function CommandTerminal({ command }: { command: string }) {
117
return (
128
<div
@@ -22,24 +18,6 @@ export function CommandTerminal({ command }: { command: string }) {
2218
overflow: "hidden",
2319
}}
2420
>
25-
<style>{`
26-
@keyframes nc-cycle {
27-
0%,
28-
20% {
29-
opacity: 1;
30-
}
31-
25%,
32-
100% {
33-
opacity: 0;
34-
}
35-
}
36-
37-
@keyframes nc-blink {
38-
50% {
39-
opacity: 0;
40-
}
41-
}
42-
`}</style>
4321
<div
4422
style={{
4523
alignItems: "center",
@@ -68,51 +46,7 @@ export function CommandTerminal({ command }: { command: string }) {
6846
</div>
6947
<div style={{ minWidth: "max-content", whiteSpace: "nowrap" }}>
7048
<span style={{ color: "#76B900", userSelect: "none" }}>$ </span>
71-
<span>{"openshell sandbox create "}</span>
72-
<span
73-
style={{
74-
display: "inline-block",
75-
height: "1.8em",
76-
minWidth: "12ch",
77-
overflow: "hidden",
78-
position: "relative",
79-
verticalAlign: "top",
80-
}}
81-
>
82-
{rotatingAgents.map((agent, index) => (
83-
<span
84-
key={agent}
85-
style={{
86-
animation: "nc-cycle 12s ease-in-out infinite",
87-
animationDelay: `${index * 3}s`,
88-
inset: "0 auto auto 0",
89-
opacity: 0,
90-
position: "absolute",
91-
whiteSpace: "nowrap",
92-
}}
93-
>
94-
{agent !== "" && (
95-
<span>
96-
{"-- "}
97-
<span style={{ color: "#76B900", fontWeight: 600 }}>
98-
{agent}
99-
</span>
100-
<span
101-
style={{
102-
animation: "nc-blink 1s step-end infinite",
103-
background: "#d4d4d8",
104-
display: "inline-block",
105-
height: "1.1em",
106-
marginLeft: "1px",
107-
verticalAlign: "text-bottom",
108-
width: "2px",
109-
}}
110-
/>
111-
</span>
112-
)}
113-
</span>
114-
))}
115-
</span>
49+
<span>openshell sandbox create</span>
11650
</div>
11751
</div>
11852
</div>

‎docs/about/installation.mdx‎

Lines changed: 21 additions & 24 deletions
Original file line numberDiff line numberDiff line change
@@ -3,12 +3,12 @@
33
# SPDX-License-Identifier: Apache-2.0
44
title: "Installation"
55
sidebar-title: "Installation"
6-
description: "Install OpenShell, choose a compute driver, and connect to a gateway."
6+
description: "Install OpenShell, choose a sandbox runtime, and connect to a gateway."
77
keywords: "Generative AI, Cybersecurity, AI Agents, Sandboxing, Installation, Setup, Gateway, Docker, Podman, MicroVM, Kubernetes"
88
position: 3
99
---
1010

11-
Install OpenShell on a local workstation, choose the compute driver that runs
11+
Install OpenShell on a local workstation, choose the runtime that runs
1212
your sandboxes, and verify the package-managed gateway configuration.
1313

1414
## Install OpenShell
@@ -23,37 +23,35 @@ The script detects your operating system and installs the OpenShell CLI, standal
2323

2424
You can also download release artifacts directly from the [OpenShell GitHub Releases](https://github.com/NVIDIA/OpenShell/releases) page.
2525

26-
### Install a prerelease
27-
28-
Prerelease packages are retained as GitHub Actions artifacts for 90 days and require an authenticated [GitHub CLI](https://cli.github.com/) session. The `pre` alias installs the latest prerelease:
29-
30-
```shell
31-
gh auth login
32-
curl -LsSf https://raw.githubusercontent.com/NVIDIA/OpenShell/main/install.sh | \
33-
OPENSHELL_VERSION=pre sh
34-
```
35-
36-
The installer rejects expired candidates, downloads only the artifact required for your platform, and installs with Debian, RPM, or Homebrew. Installed packages retain the candidate's exact version, such as `0.1.0-pre.3`. Prerelease tags do not create entries on the GitHub Releases page.
26+
Use `openshell status` to confirm the CLI can reach the gateway.
3727

38-
The `openshell` package on PyPI provides the Python SDK only. It does not install the `openshell` CLI. Add the SDK to a Python project with:
28+
## Release Cadence
3929

40-
```shell
41-
uv add openshell
42-
```
30+
OpenShell publishes stable versions as coordinated release sets. The default
31+
installer selects the newest stable release, and the `latest` documentation
32+
channel follows that release. Use the same version of the gateway, compute and
33+
credential drivers, supervisors, CLI, and SDK clients together.
4334

44-
Use `openshell status` to confirm the CLI can reach the gateway.
35+
Between stable releases, numbered prereleases such as `0.1.0-pre.3` provide
36+
evaluation checkpoints. Rolling development builds track successful releases
37+
from `main` and use versions such as `0.0.0-dev.<commit-sha>`. Prerelease and
38+
development builds may change before the next stable release; their matching
39+
documentation is published in the `dev` channel.
4540

46-
## Supported Compute Drivers
41+
## Supported Runtimes
4742

48-
OpenShell supports several local compute drivers. Package-managed gateways leave the driver unset by default so the gateway can auto-detect an available driver. Set `compute_driver` in the gateway TOML when you need to pin a specific driver.
43+
OpenShell supports several sandbox runtimes. Package-managed gateways leave the
44+
runtime unset by default so the gateway can auto-detect an available backend.
45+
Set `compute_driver` in the gateway TOML when you need to pin a specific
46+
runtime.
4947

50-
| Compute Driver | How It Is Configured | System Requirements |
48+
| Runtime | How It Is Configured | System Requirements |
5149
|---|---|---|
5250
| Podman | The gateway is configured to create rootless Podman containers through the Podman API socket. | Linux with Podman 5.x, cgroups v2, rootless networking, and an active Podman user socket. |
5351
| Docker | The gateway is configured to create containers through Docker Desktop or Docker Engine. | Docker Desktop or Docker Engine 28.0 or later on the gateway host. |
5452
| MicroVM | The gateway is configured to create VM-backed sandboxes. | Host virtualization support. MicroVM uses Hypervisor.framework on macOS, KVM on Linux, and QEMU for GPU-backed sandboxes on Linux. |
5553

56-
For detailed driver behavior, refer to [Sandbox Compute Drivers](/reference/sandbox-compute-drivers). For gateway and sandbox operations, refer to [Gateways](/sandboxes/manage-gateways) and [Sandboxes](/sandboxes/manage-sandboxes).
54+
For detailed runtime behavior, refer to [Sandbox Runtimes](/reference/sandbox-compute-drivers). For gateway and sandbox operations, refer to [Gateways](/sandboxes/manage-gateways) and [Sandboxes](/sandboxes/manage-sandboxes).
5755

5856
## macOS
5957

@@ -192,8 +190,7 @@ for preflight details and manual schema-v1 migration steps.
192190

193191
## Next Steps
194192

195-
- To launch an agent, refer to [Run Your First Agent](/about/run-an-agent).
196-
- To create your first sandbox, refer to the [Quickstart](/get-started/quickstart).
193+
- To prepare an image and launch an agent, refer to [Run Your First Agent](/about/run-an-agent).
197194
- To run the gateway as a container without the installer, refer to [Running the Gateway as a Container](/reference/container-gateway).
198195
- To register, select, and inspect gateways, refer to [Gateways](/sandboxes/manage-gateways).
199196
- To supply API keys or tokens, refer to [Manage Providers](/sandboxes/manage-providers).

‎docs/about/overview.mdx‎

Lines changed: 3 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -11,14 +11,9 @@ position: 1
1111
NVIDIA OpenShell is an open-source runtime for executing autonomous AI agents in sandboxed environments with kernel-level isolation. It combines sandbox runtime controls and a declarative YAML policy so teams can run agents without giving them unrestricted access to local files, credentials, and external networks.
1212

1313
<Note>
14-
OpenShell 0.1.0 is almost ready. It brings:
14+
New in OpenShell 0.1.0 is a [stable release cadence](/about/installation#release-cadence), a stronger [security model](/about/how-it-works), and an expanded [extension surface](/extensibility/extension-negotiation), along with much more.
1515

16-
- A stable release cadence.
17-
- An improved security model.
18-
- An expanded extension surface.
19-
- New APIs.
20-
21-
Coming from 0.0.x? Read the [0.1.0 upgrade guide](/upgrade/0-1-0) before upgrading.
16+
See our [upgrade guide](/upgrade/0-1-0) for everything that's changed.
2217
</Note>
2318

2419
## Why OpenShell Exists
@@ -65,5 +60,5 @@ OpenShell supports a range of agent deployment patterns.
6560
Explore these topics to go deeper:
6661

6762
- To understand the runtime architecture, refer to [How OpenShell Works](/about/how-it-works).
68-
- To install the CLI and create your first sandbox, refer to the [Quickstart](/get-started/quickstart).
63+
- To prepare an image and launch an agent, refer to [Run Your First Agent](/about/run-an-agent).
6964
- To learn how OpenShell enforces policy controls across protection layers, refer to [Customize Sandbox Policies](/sandboxes/policies).

‎docs/about/run-an-agent.mdx‎

Lines changed: 6 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -47,8 +47,10 @@ Review a profile before importing it, especially its executable paths and
4747
network endpoints.
4848

4949
```shell
50-
openshell provider profile import -f provider-profile.yaml --global
51-
openshell provider list-profiles
50+
curl -LsSfO https://raw.githubusercontent.com/NVIDIA/OpenShell/main/providers/claude-code.yaml
51+
openshell profile import -f claude-code.yaml --global
52+
ANTHROPIC_API_KEY=<your-key> \
53+
openshell provider create --name my-claude --type claude-code --from-existing
5254
```
5355

5456
The repository includes example profiles in
@@ -59,14 +61,14 @@ profile schema and import workflow.
5961

6062
## Launch the Agent
6163

62-
Pass the agent command after `--` and attach the provider profiles it needs.
64+
Pass the agent command after `--` and attach the provider instances it needs.
6365
For example, this command starts Claude Code from an image your team built with
6466
the `claude` executable installed:
6567

6668
```shell
6769
openshell sandbox create \
6870
--from registry.example.com/team/claude-code:1.0 \
69-
--provider claude-code \
71+
--provider my-claude \
7072
-- claude
7173
```
7274

@@ -122,8 +124,6 @@ policy after reviewing the requested access.
122124

123125
## Next Steps
124126

125-
- For a complete image-to-sandbox workflow, refer to the
126-
[Quickstart](/get-started/quickstart).
127127
- For sandbox lifecycle, resources, templates, files, and connectivity, refer
128128
to [Sandboxes](/sandboxes/manage-sandboxes).
129129
- For the restrictive fallback policy, refer to

‎docs/extensibility/drivers.mdx‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -20,7 +20,7 @@ socket and negotiates its protocol version and capabilities before serving
2020
requests.
2121

2222
For built-in driver configuration and behavior, refer to
23-
[Compute Drivers](/reference/sandbox-compute-drivers).
23+
[Runtimes](/reference/sandbox-compute-drivers).
2424

2525
## Credential Drivers
2626

‎docs/extensibility/isolation-backends.mdx‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -23,4 +23,4 @@ sandboxes through the same gateway API.
2323

2424
For the deployment-level runtime architecture, refer to
2525
[Sandbox Runtime](/kubernetes/sandbox-runtime). For driver-specific workload
26-
behavior, refer to [Compute Drivers](/reference/sandbox-compute-drivers).
26+
behavior, refer to [Runtimes](/reference/sandbox-compute-drivers).

‎docs/get-started/quickstart.mdx‎

Lines changed: 0 additions & 100 deletions
This file was deleted.

0 commit comments

Comments
 (0)