NVIDIA / OpenShell
NVIDIA / OpenShell
Important: New in OpenShell 0.1.x: a stable release cadence, new isolation primitives, an expanded extension surface, and new APIs. Read the 0.1.0 upgrade guide. 重要提示: OpenShell 0.1.x 版本的新特性包括:稳定的发布节奏、全新的隔离原语、扩展的扩展接口以及新的 API。请阅读 0.1.0 升级指南。
OpenShell is the safe, private runtime for fleets of autonomous AI agents. Agents are most useful when they can read files, install packages, call APIs, and use credentials. OpenShell gives them that capability without giving them unrestricted access to your data, secrets, or network. You declare what each agent can touch in a policy, and OpenShell enforces it. OpenShell 是专为自主 AI 智能体集群设计的安全、私密运行时。智能体在能够读取文件、安装软件包、调用 API 和使用凭据时最为高效。OpenShell 在赋予智能体这些能力的同时,不会给予它们对你的数据、密钥或网络的无限制访问权限。你可以在策略中声明每个智能体可以触达的范围,OpenShell 将负责强制执行。
How It Works
工作原理
OpenShell governs what agents can do in two ways: it instruments the kernel to enforce policy on every file access, system call, and network connection at runtime, and it uses formal verification to check what a policy change would allow before it is applied. OpenShell 通过两种方式管理智能体的行为:它通过检测内核,在运行时对每一次文件访问、系统调用和网络连接强制执行策略;并利用形式化验证,在应用策略变更前检查其允许的操作范围。
Kernel-level enforcement. Each agent runs in an isolated sandbox. Kernel controls confine which files it can access and which system calls it can make, and every network connection passes through a policy check before it leaves the sandbox. Agents never see real credentials; OpenShell adds them only to requests bound for approved endpoints. 内核级强制执行。 每个智能体都在隔离的沙箱中运行。内核控制限制了智能体可以访问的文件和可以进行的系统调用,且每一条网络连接在离开沙箱前都会经过策略检查。智能体永远无法看到真实的凭据;OpenShell 仅在发往已批准端点的请求中添加凭据。
Formally verified policy changes. Before a policy change is approved, OpenShell uses formal verification to flag risky new access it would grant, such as reaching a new host with credentials or calling a new API method, so those changes wait for human review. See Architecture for how the gateway, supervisor, and sandbox fit together. 形式化验证策略变更。 在批准策略变更之前,OpenShell 会使用形式化验证来标记其可能带来的风险访问(例如使用凭据访问新主机或调用新的 API 方法),从而确保这些变更必须经过人工审核。有关网关、监督器和沙箱如何协同工作,请参阅“架构”部分。
Quickstart
快速开始
You need Linux, macOS on Apple Silicon, or Windows with WSL 2 (experimental), plus Docker, Podman, or host virtualization. See the Support Matrix for details. 你需要 Linux、Apple Silicon 架构的 macOS,或安装了 WSL 2(实验性)的 Windows,以及 Docker、Podman 或主机虚拟化环境。详情请参阅“支持矩阵”。
curl -LsSf https://raw.githubusercontent.com/NVIDIA/OpenShell/main/install.sh | sh
openshell sandbox create --name demo
The installer sets up the CLI and a local gateway. The default sandbox image is minimal Ubuntu with no agent installed. To run a real agent, follow Run Your First Agent: it runs OpenCode against a free OpenRouter model and shows how to approve new access as the agent needs it. 安装程序会设置 CLI 和本地网关。默认的沙箱镜像是最小化的 Ubuntu,未安装任何智能体。要运行真实的智能体,请参考“运行你的第一个智能体”:它会针对免费的 OpenRouter 模型运行 OpenCode,并演示如何根据智能体的需求批准新的访问权限。
Explore Further
深入探索
- Sandboxes: images, runtimes, GPUs, and lifecycle.
- 沙箱: 镜像、运行时、GPU 和生命周期。
- Policies: filesystem, network, and process rules, with the advisor and prover for reviewing changes.
- 策略: 文件系统、网络和进程规则,包含用于审查变更的顾问(advisor)和证明器(prover)。
- Providers: credentials that work only at approved endpoints, including inference.
- 提供者: 仅在已批准端点(包括推理服务)工作的凭据。
- Gateways: the control plane for sandboxes, policy, and access.
- 网关: 沙箱、策略和访问的控制平面。
- Kubernetes: deploy the gateway with Helm. Your CNI must enforce NetworkPolicy.
- Kubernetes: 使用 Helm 部署网关。你的 CNI 必须强制执行 NetworkPolicy。
- Extensibility: middleware, interceptors, and compute drivers.
- 可扩展性: 中间件、拦截器和计算驱动程序。
- Tutorials: step-by-step policy and agent walkthroughs.
- 教程: 分步策略和智能体操作指南。
- Prerelease and development builds: try an upcoming release or the latest commit on main.
- 预发布和开发版本: 尝试即将发布的版本或主分支上的最新提交。
Agent Skills
智能体技能
Install the public OpenShell skills for your coding agent: 为你的编码智能体安装公共 OpenShell 技能:
npx skills add NVIDIA/OpenShell
The skills teach your agent to drive the OpenShell CLI, write sandbox policies, and debug gateways and inference routing. They live in skills/ and work without an OpenShell source checkout.
这些技能教会你的智能体如何驱动 OpenShell CLI、编写沙箱策略以及调试网关和推理路由。它们位于 skills/ 目录下,无需检出 OpenShell 源码即可工作。
SDKs
SDK
SDKs connect applications to an OpenShell gateway. They do not install the CLI. Use the same OpenShell release for the SDK and the gateway when possible. SDK 用于将应用程序连接到 OpenShell 网关。它们不会安装 CLI。请尽可能在 SDK 和网关中使用相同的 OpenShell 版本。
| Language | Install | Docs |
|---|---|---|
| Python | uv add openshell | README |
| TypeScript | npm install @nvidia/openshell-sdk (GitHub Packages) | README |
| Go | go get github.com/NVIDIA/OpenShell/sdk/go@latest | README |
| Rust | cargo add openshell-sdk --git ... | README |
Installation and usage
安装与使用
- Questions and discussion: GitHub Discussions
- 问题与讨论: GitHub Discussions
- Bug reports and feature requests: GitHub Issues, using the issue templates
- Bug 报告与功能请求: GitHub Issues(请使用 issue 模板)
- Security vulnerabilities: follow SECURITY.md. Do not open a GitHub issue.
- 安全漏洞: 请遵循 SECURITY.md。请勿开启 GitHub issue。
- Roadmap: OpenShell Roadmap and the RFC board
- 路线图: OpenShell 路线图和 RFC 看板
- Try it in the cloud: Brev Launchable
- 云端试用: Brev Launchable
OpenShell is built agent-first: it is developed with the same agent-driven workflows it enables. See CONTRIBUTING.md for development setup and the contribution workflow, and AGENTS.md for the contributor agent skills and workflow chains. OpenShell 是“智能体优先”构建的:它的开发过程本身就采用了它所支持的智能体驱动工作流。有关开发环境设置和贡献工作流,请参阅 CONTRIBUTING.md;有关贡献者智能体技能和工作流链,请参阅 AGENTS.md。
Telemetry
遥测
OpenShell collects anonymous telemetry, limited to operational categories and counts, to help improve the project. It does not collect sandbox names, hostnames, file paths, prompts, credentials, provider or model names, or user content. To disable it, set OPENSHELL_TELEMETRY_ENABLED=false on the gateway, or server.telemetryEnabled=false for Helm installs. You can also compile telemetry out entirely. See Telemetry for details and the community telemetry reports for published usage trends.
OpenShell 收集匿名遥测数据,仅限于操作类别和计数,以帮助改进项目。它不会收集沙箱名称、主机名、文件路径、提示词、凭据、提供商或模型名称,以及用户内容。要禁用此功能,请在网关上设置 OPENSHELL_TELEMETRY_ENABLED=false,或在 Helm 安装中设置 server.telemetryEnabled=false。你也可以在编译时完全移除遥测功能。详情请参阅“遥测”文档,以及查看社区遥测报告以了解已发布的趋势。
Notice and Disclaimer
注意事项与免责声明
This software automatically retrieves, accesses or interacts with external materials. Those retrieved materials are not distributed with this software and are governed solely by separate terms, conditions and licenses. You are solely responsible for finding, reviewing and complying with all applicable terms, conditions, and licenses, and for verifying the security, integrity and suitability of any retrieved materials for your specific use case. This software is provided “AS IS”, without warranty of any kind. The author makes no representations or warranties regarding any retrieved materials, and assumes no liability for any losses, damages, liabilities or legal consequences from your use or inability to use this software or any retrieved materials. Use this software and the retrieved materials at your own risk. 本软件会自动检索、访问或与外部材料交互。这些检索到的材料不随本软件分发,并受各自独立的条款、条件和许可协议约束。你有责任自行查找、审查并遵守所有适用的条款、条件和许可,并验证任何检索到的材料对于你特定用例的安全性、完整性和适用性。本软件按“原样”提供,不附带任何形式的保证。作者不对任何检索到的材料作出任何陈述或保证,也不对因你使用或无法使用本软件或任何检索到的材料而导致的任何损失、损害、责任或法律后果承担任何责任。使用本软件及检索到的材料风险自负。
License
许可协议
This project is licensed under the Apache License 2.0. 本项目采用 Apache License 2.0 许可协议。