NVIDIA OpenShell is an open-source runtime for executing fleets of autonomous AI agents in sandboxed environments with kernel-level isolation. It combines sandbox runtime controls and a declarative YAML policy so teams can run agents without giving them unrestricted access to local files, credentials, and external networks.
New in OpenShell 0.1.x: a [stable release cadence](https://docs.nvidia.com/openshell/about/support-matrix#releases), new [isolation primitives](https://docs.nvidia.com/openshell/about/architecture), and an expanded [extension surface](https://docs.nvidia.com/openshell/extensibility/overview), along with much more.
See our [upgrade guide](https://docs.nvidia.com/openshell/upgrade/0-1-0) for everything that’s changed.
Why OpenShell Exists #
AI agents are most useful when they can read files, install packages, call APIs, and use credentials. That same access can create material risk. OpenShell is designed for this tradeoff: preserve agent capability while enforcing explicit controls over what the agent can access.
Common Risks and Controls #
The table below summarizes common failure modes and how OpenShell mitigates them.
Protection Layers at a Glance #
OpenShell applies defense in depth across the following policy domains.
For details, refer to Sandbox Policies and Default Policy.
Common Use Cases #
OpenShell supports a range of agent deployment patterns.
Next Steps #
Explore these topics to go deeper:
- To understand the runtime architecture, refer to Architecture .
- To prepare an image and launch an agent, refer to Run Your First Agent .
- To learn how OpenShell enforces policy controls across protection layers, refer to Sandbox Policies .