Who OpenShell is for#
Secure coding agents
Run Claude Code, OpenCode, Codex, or GitHub Copilot CLI with constrained file and network access, so an agent can work in a repository without reaching the rest of your machine.
Skip if:
You only run agents on disposable cloud machines that hold no secrets or private code.
Private enterprise development
Grant selected sandboxes access to self-hosted or private model endpoints while keeping sensitive context under your control.
Skip if:
You already send all model traffic to a public provider and have no data residency requirement.
Compliance and audit
Treat policy YAML as version-controlled security controls that reviewers can read, diff, and audit alongside application code.
Skip if:
Your security reviews happen outside version control and cannot consume policy files.
The problem it solves#
Autonomous agents need real access to be useful: files to read, packages to install, APIs to call, and credentials to authenticate with. Giving them that access on a developer machine or shared server creates risk. An agent can upload source code to an unauthorized endpoint, read local secrets such as SSH keys or cloud credentials, send data to an unapproved model provider, or attempt privilege escalation with sudo or dangerous syscalls. Hosted sandbox services reduce that risk by moving execution elsewhere, but then your code and context run on someone else's infrastructure. OpenShell keeps the agent capable while enforcing explicit, reviewable limits on what it can reach, on hardware you control.
How it solves it#
Kernel-level isolation
Each agent runs in its own sandbox. Kernel controls confine which files it can access and which system calls it can make, using Landlock for filesystem limits and seccomp restrictions with an unprivileged process identity to block escalation.
Declarative YAML policies
Filesystem, network, and process rules live in policy files. Filesystem and process rules are locked at sandbox creation, and network rules are hot-reloadable at runtime. Because policies are plain YAML, they can be version-controlled and audited.
Credential handling through providers
Agents never see real credentials. Provider profiles resolve opaque placeholders only at authorized endpoints, so a leaked prompt or file cannot expose a working secret. Attachments, rotation, and revocation update at runtime.
Formally verified policy changes
Before a policy change is approved, OpenShell uses formal verification to flag risky new access, such as reaching a new host with credentials or calling a new API method. Those changes wait for human review.
SDKs and extension points
Python, TypeScript, Go, and Rust SDKs connect applications to a gateway. Middleware, gateway interceptors, and compute drivers let you extend the runtime, and it ships OCSF JSON log export for observability.
Strengths and trade-offs#
Strengths
- Enforcement below the agentControls are applied by the kernel to file access, system calls, and network connections, so they hold regardless of which agent or model runs inside the sandbox.
- Works with the agents people already useThe docs list Claude Code, OpenCode, Codex, and GitHub Copilot CLI as supported use cases, and you can use the default Ubuntu image or bring your own containerized runtime.
- Runs where you chooseA local gateway runs on Linux, macOS on Apple Silicon, or WSL 2 with Docker, Podman, or host virtualization, and a Helm chart covers Kubernetes, including OpenShift guidance in the docs.
- Active and permissively licensedThe Apache-2.0 repository is written in Rust and had a push on the day this page was researched. The 0.1.x line adds a stable release cadence.
Trade-offs
- -Early versionThe latest release is v0.1.2 and the project describes 0.1.x as introducing new isolation primitives and APIs, with an upgrade guide for the changes. Expect breaking changes as it matures.
- -Platform limitsWindows support through WSL 2 is marked experimental. On Kubernetes, your CNI must enforce NetworkPolicy, so cluster setup matters for the isolation guarantees.
- -You operate itUnlike a hosted sandbox service, you run and upgrade the gateway yourself, and the repository has 498 open issues at the time of writing.
- -Anonymous telemetry on by defaultOpenShell collects anonymous operational counts. It does not collect prompts, credentials, file paths, or user content, and you can disable it with OPENSHELL_TELEMETRY_ENABLED=false or compile it out.
OpenShell vs alternatives#
OpenShell vs E2B
E2B is the paid product OpenShell is linked to as an alternative. The two overlap on one job: giving an AI agent an isolated place to run code.
Where execution happens
OpenShell runs on infrastructure you control. The installer sets up a local gateway, and a Helm chart deploys the gateway to Kubernetes. With a commercial hosted sandbox service, code and context run on the vendor's infrastructure. If your agents touch private repositories or internal model endpoints, keeping execution in-house is the main reason to pick OpenShell.
Policy and credentials
OpenShell is built around a declarative YAML policy covering filesystem, network, and process rules, with credentials injected only at approved endpoints. Network rules can be changed at runtime, and risky policy changes are flagged for human review. Check the current documentation of any paid tool you compare against for how it exposes similar controls.
Cost and effort
OpenShell is free under Apache-2.0, but you run, upgrade, and monitor it yourself, and it is still at v0.1.2. A paid hosted service trades money for less operational work. Choose OpenShell when data control and auditable policy matter more than avoiding that work.
Quick start#
Setup needs Docker, Podman, or host virtualization; the installer adds the CLI and a local gateway.
```bash
curl -LsSf https://raw.githubusercontent.com/NVIDIA/OpenShell/main/install.sh | sh
openshell sandbox create --name demo
```What it's built on#
- Languages
- GoPythonRustTypeScript
FAQ#
Is OpenShell really open source?
Yes. The repository is licensed under Apache-2.0, and you can run it on your own machines or in your own Kubernetes cluster.
Which agents can run inside it?
The docs name Claude Code, OpenCode, Codex, and GitHub Copilot CLI. The default sandbox image is minimal Ubuntu with no agent installed, so you install the agent you want or bring your own container image.
What do I need to run it?
Linux, macOS on Apple Silicon, or Windows with WSL 2 (experimental), plus Docker, Podman, or host virtualization. The install script sets up the CLI and a local gateway.
How does it handle credentials?
Agents never see real credentials. OpenShell adds them only to requests bound for endpoints approved by a provider profile, and attachments, rotation, and revocation update at runtime.
Similar open-source tools#
substrate
Kubernetes-native sandbox runtime for AI agent execution
Omnara
Open-source agent deployment API. Self-host or use Omnara Cloud.
openbao
Open source secret management governed by the Linux Foundation
ax
Declarative runtime for autonomous agent workloads
dify
Visual AI workflow builder with RAG, agents, and self-hosting
security-audit-skill
Multi-phase security audits with machine-readable findings

