You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Commit dc565bf
Browse filesBrowse the repository at this point in the historyBrowse files
> **OpenShell 0.1.0 is coming soon.**[Track progress in the 0.1.0 milestone](https://github.com/NVIDIA/OpenShell/milestone/10), [read the prerelease documentation](https://docs.nvidia.com/openshell/dev/index.html), or [install a prerelease](#prerelease-and-development-builds).
18
+
> **New in OpenShell 0.1.0:** a stable release cadence, an improved security model, an expanded extension surface, and new APIs. [Read the 0.1.0 upgrade guide](https://docs.nvidia.com/openshell/latest/upgrade/0-1-0).
19
19
20
20
OpenShell is the safe, private runtime for autonomous AI agents. It provides sandboxed execution environments that protect your data, credentials, and infrastructure — governed by declarative YAML policies that prevent unauthorized file access, data exfiltration, and uncontrolled network activity.
21
21
22
22
OpenShell is built agent-first. It ships public agent skills for using and operating OpenShell, plus separate repository-aware workflows for contributors and maintainers.
23
23
24
-
## Quickstart
24
+
## Install OpenShell
25
25
26
26
### Prerequisites
27
27
@@ -190,20 +190,13 @@ Docker-backed GPU sandboxes auto-select CDI when available and otherwise fall ba
190
190
191
191
**Requirements:** NVIDIA drivers and the [NVIDIA Container Toolkit](https://docs.nvidia.com/datacenter/cloud-native/container-toolkit/latest/install-guide.html) must be installed on the host. The sandbox image itself must include the appropriate GPU drivers and libraries for your workload — the default Ubuntu image does not. See the [BYOC example](https://github.com/NVIDIA/OpenShell/tree/main/examples/bring-your-own-container) for building a custom sandbox image with GPU support.
192
192
193
-
## Supported Agents
193
+
## Running Agents
194
194
195
195
OpenShell can run Linux agents packaged in OCI images. The default Ubuntu
196
196
workload does not bundle agent CLIs. Build or select an image containing your
197
-
agent, then authorize its binary paths, service endpoints, and credentials.
198
-
199
-
| Agent | Integration |
200
-
| ----- | ----------- |
201
-
|[Claude Code](https://docs.anthropic.com/en/docs/claude-code)| Package Claude Code in a workload image and attach a `claude-code` provider or another endpoint-bearing model profile. |
202
-
|[OpenCode](https://opencode.ai/)| Package OpenCode in a workload image and attach its model provider and policy. |
203
-
|[Codex](https://developers.openai.com/codex)| Package Codex in a workload image and attach an OpenAI provider and policy. |
204
-
|[GitHub Copilot CLI](https://docs.github.com/en/copilot/github-copilot-in-the-cli)| Package the CLI in a workload image and attach GitHub credentials and policy. |
205
-
|[OpenClaw](https://openclaw.ai/)| Use the [NemoClaw](https://github.com/NVIDIA/NemoClaw) blueprint. |
206
-
|[Hermes Agent](https://github.com/NousResearch/hermes-agent)| Use the [NemoClaw](https://github.com/NVIDIA/NemoClaw) blueprint. |
197
+
agent, then authorize its binary paths, service endpoints, and credentials. See
198
+
[Run Your First Agent](https://docs.nvidia.com/openshell/latest/about/run-an-agent)
199
+
for the image, provider, and policy workflow.
207
200
208
201
## Key Commands
209
202
@@ -284,7 +277,7 @@ Agent implementation is human-directed: a user may request a phase directly, or
284
277
## Learn More
285
278
286
279
-[Full Documentation](https://docs.nvidia.com/openshell/latest/index.html) — overview, architecture, tutorials, and reference
287
-
-[Quickstart](https://docs.nvidia.com/openshell/latest/get-started/quickstart) — detailed install and first sandbox walkthrough
280
+
-[Run Your First Agent](https://docs.nvidia.com/openshell/latest/about/run-an-agent) — prepare an image, attach providers, and launch an agent
Install OpenShell on a local workstation, choose the compute driver that runs
11
+
Install OpenShell on a local workstation, choose the runtime that runs
12
12
your sandboxes, and verify the package-managed gateway configuration.
13
13
14
14
## Install OpenShell
@@ -23,37 +23,35 @@ The script detects your operating system and installs the OpenShell CLI, standal
23
23
24
24
You can also download release artifacts directly from the [OpenShell GitHub Releases](https://github.com/NVIDIA/OpenShell/releases) page.
25
25
26
-
### Install a prerelease
27
-
28
-
Prerelease packages are retained as GitHub Actions artifacts for 90 days and require an authenticated [GitHub CLI](https://cli.github.com/) session. The `pre` alias installs the latest prerelease:
The installer rejects expired candidates, downloads only the artifact required for your platform, and installs with Debian, RPM, or Homebrew. Installed packages retain the candidate's exact version, such as `0.1.0-pre.3`. Prerelease tags do not create entries on the GitHub Releases page.
26
+
Use `openshell status` to confirm the CLI can reach the gateway.
37
27
38
-
The `openshell` package on PyPI provides the Python SDK only. It does not install the `openshell` CLI. Add the SDK to a Python project with:
28
+
## Release Cadence
39
29
40
-
```shell
41
-
uv add openshell
42
-
```
30
+
OpenShell publishes stable versions as coordinated release sets. The default
31
+
installer selects the newest stable release, and the `latest` documentation
32
+
channel follows that release. Use the same version of the gateway, compute and
33
+
credential drivers, supervisors, CLI, and SDK clients together.
43
34
44
-
Use `openshell status` to confirm the CLI can reach the gateway.
35
+
Between stable releases, numbered prereleases such as `0.1.0-pre.3` provide
36
+
evaluation checkpoints. Rolling development builds track successful releases
37
+
from `main` and use versions such as `0.0.0-dev.<commit-sha>`. Prerelease and
38
+
development builds may change before the next stable release; their matching
39
+
documentation is published in the `dev` channel.
45
40
46
-
## Supported Compute Drivers
41
+
## Supported Runtimes
47
42
48
-
OpenShell supports several local compute drivers. Package-managed gateways leave the driver unset by default so the gateway can auto-detect an available driver. Set `compute_driver` in the gateway TOML when you need to pin a specific driver.
43
+
OpenShell supports several sandbox runtimes. Package-managed gateways leave the
44
+
runtime unset by default so the gateway can auto-detect an available backend.
45
+
Set `compute_driver` in the gateway TOML when you need to pin a specific
46
+
runtime.
49
47
50
-
|Compute Driver| How It Is Configured | System Requirements |
48
+
|Runtime| How It Is Configured | System Requirements |
51
49
|---|---|---|
52
50
| Podman | The gateway is configured to create rootless Podman containers through the Podman API socket. | Linux with Podman 5.x, cgroups v2, rootless networking, and an active Podman user socket. |
53
51
| Docker | The gateway is configured to create containers through Docker Desktop or Docker Engine. | Docker Desktop or Docker Engine 28.0 or later on the gateway host. |
54
52
| MicroVM | The gateway is configured to create VM-backed sandboxes. | Host virtualization support. MicroVM uses Hypervisor.framework on macOS, KVM on Linux, and QEMU for GPU-backed sandboxes on Linux. |
55
53
56
-
For detailed driver behavior, refer to [Sandbox Compute Drivers](/reference/sandbox-compute-drivers). For gateway and sandbox operations, refer to [Gateways](/sandboxes/manage-gateways) and [Sandboxes](/sandboxes/manage-sandboxes).
54
+
For detailed runtime behavior, refer to [Sandbox Runtimes](/reference/sandbox-compute-drivers). For gateway and sandbox operations, refer to [Gateways](/sandboxes/manage-gateways) and [Sandboxes](/sandboxes/manage-sandboxes).
57
55
58
56
## macOS
59
57
@@ -192,8 +190,7 @@ for preflight details and manual schema-v1 migration steps.
192
190
193
191
## Next Steps
194
192
195
-
- To launch an agent, refer to [Run Your First Agent](/about/run-an-agent).
196
-
- To create your first sandbox, refer to the [Quickstart](/get-started/quickstart).
193
+
- To prepare an image and launch an agent, refer to [Run Your First Agent](/about/run-an-agent).
197
194
- To run the gateway as a container without the installer, refer to [Running the Gateway as a Container](/reference/container-gateway).
198
195
- To register, select, and inspect gateways, refer to [Gateways](/sandboxes/manage-gateways).
199
196
- To supply API keys or tokens, refer to [Manage Providers](/sandboxes/manage-providers).
Copy file name to clipboardExpand all lines: docs/about/overview.mdx
+3-8Lines changed: 3 additions & 8 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -11,14 +11,9 @@ position: 1
11
11
NVIDIA OpenShell is an open-source runtime for executing autonomous AI agents in sandboxed environments with kernel-level isolation. It combines sandbox runtime controls and a declarative YAML policy so teams can run agents without giving them unrestricted access to local files, credentials, and external networks.
12
12
13
13
<Note>
14
-
OpenShell 0.1.0 is almost ready. It brings:
14
+
New in OpenShell 0.1.0 is a [stable release cadence](/about/installation#release-cadence), a stronger [security model](/about/how-it-works), and an expanded [extension surface](/extensibility/extension-negotiation), along with much more.
15
15
16
-
- A stable release cadence.
17
-
- An improved security model.
18
-
- An expanded extension surface.
19
-
- New APIs.
20
-
21
-
Coming from 0.0.x? Read the [0.1.0 upgrade guide](/upgrade/0-1-0) before upgrading.
16
+
See our [upgrade guide](/upgrade/0-1-0) for everything that's changed.
22
17
</Note>
23
18
24
19
## Why OpenShell Exists
@@ -65,5 +60,5 @@ OpenShell supports a range of agent deployment patterns.
65
60
Explore these topics to go deeper:
66
61
67
62
- To understand the runtime architecture, refer to [How OpenShell Works](/about/how-it-works).
68
-
- To install the CLI and create your first sandbox, refer to the [Quickstart](/get-started/quickstart).
63
+
- To prepare an image and launch an agent, refer to [Run Your First Agent](/about/run-an-agent).
69
64
- To learn how OpenShell enforces policy controls across protection layers, refer to [Customize Sandbox Policies](/sandboxes/policies).
0 commit comments