Open Source Alternatives LogoOpen Source Alternatives
AlternativesBlogAdvertise
Open Source Alternatives LogoOpen Source Alternatives

Stay Updated

Subscribe to our newsletter for the latest news and updates about Alternatives

Open Source Alternatives LogoOpen Source Alternatives

Handpicked Open Source Alternatives to Paid Softwares

Product
  • Categories
  • Tag
  • Advertise
Resources
  • Blog
  • Collection
  • Submit
  • Advertise your tool
Company
  • Privacy Policy
  • Terms of Service
  • Refund Policy
  • Sitemap
Alternatives
  • Claude Code
  • Jira
  • Notion
  • Slack
  • Linear
  • Wispr Flow
  • All alternatives
Copyright © 2026 All Rights Reserved.
Home/Categories/AI & Machine Learning/OpenShell
icon of OpenShell

OpenShell

Open source alternative to E2B

Run autonomous AI agents in kernel-isolated sandboxes with declarative YAML policies for files, network access, and credentials.

10.6K starsRustApache-2.0Active this week
Visit websiteGitHub repoDeployDeploy on Hostinger
Contents
  1. 01Who OpenShell is for
  2. 02The problem it solves
  3. 03How it solves it
  4. 04Strengths and trade-offs
  5. 05OpenShell vs alternatives
  6. 06Quick start
  7. 07Tech stack
  8. 08FAQ
  9. 09Similar open-source tools
TL;DR

OpenShell is an Apache-2.0 runtime from NVIDIA that runs autonomous AI agents in sandboxes with kernel-level isolation. A declarative YAML policy controls which files an agent can read, which network destinations it can reach, and which credentials it can use. It installs with a single script, runs locally on Docker, Podman, or host virtualization, and deploys to Kubernetes with Helm. It is a good fit for teams that want to run coding agents on their own infrastructure. The project is at v0.1.2, so expect fast change.Apache-2.0 · Rust · 10.6K stars · Active this week

who it's for

Who OpenShell is for#

Secure coding agents

Run Claude Code, OpenCode, Codex, or GitHub Copilot CLI with constrained file and network access, so an agent can work in a repository without reaching the rest of your machine.

Skip if:

You only run agents on disposable cloud machines that hold no secrets or private code.

Private enterprise development

Grant selected sandboxes access to self-hosted or private model endpoints while keeping sensitive context under your control.

Skip if:

You already send all model traffic to a public provider and have no data residency requirement.

Compliance and audit

Treat policy YAML as version-controlled security controls that reviewers can read, diff, and audit alongside application code.

Skip if:

Your security reviews happen outside version control and cannot consume policy files.

the problem

The problem it solves#

Autonomous agents need real access to be useful: files to read, packages to install, APIs to call, and credentials to authenticate with. Giving them that access on a developer machine or shared server creates risk. An agent can upload source code to an unauthorized endpoint, read local secrets such as SSH keys or cloud credentials, send data to an unapproved model provider, or attempt privilege escalation with sudo or dangerous syscalls. Hosted sandbox services reduce that risk by moving execution elsewhere, but then your code and context run on someone else's infrastructure. OpenShell keeps the agent capable while enforcing explicit, reviewable limits on what it can reach, on hardware you control.

how OpenShell solves it

How it solves it#

Kernel-level isolation

Each agent runs in its own sandbox. Kernel controls confine which files it can access and which system calls it can make, using Landlock for filesystem limits and seccomp restrictions with an unprivileged process identity to block escalation.

Declarative YAML policies

Filesystem, network, and process rules live in policy files. Filesystem and process rules are locked at sandbox creation, and network rules are hot-reloadable at runtime. Because policies are plain YAML, they can be version-controlled and audited.

Credential handling through providers

Agents never see real credentials. Provider profiles resolve opaque placeholders only at authorized endpoints, so a leaked prompt or file cannot expose a working secret. Attachments, rotation, and revocation update at runtime.

Formally verified policy changes

Before a policy change is approved, OpenShell uses formal verification to flag risky new access, such as reaching a new host with credentials or calling a new API method. Those changes wait for human review.

SDKs and extension points

Python, TypeScript, Go, and Rust SDKs connect applications to a gateway. Middleware, gateway interceptors, and compute drivers let you extend the runtime, and it ships OCSF JSON log export for observability.

strengths · trade-offs

Strengths and trade-offs#

Strengths

  • Enforcement below the agentControls are applied by the kernel to file access, system calls, and network connections, so they hold regardless of which agent or model runs inside the sandbox.
  • Works with the agents people already useThe docs list Claude Code, OpenCode, Codex, and GitHub Copilot CLI as supported use cases, and you can use the default Ubuntu image or bring your own containerized runtime.
  • Runs where you chooseA local gateway runs on Linux, macOS on Apple Silicon, or WSL 2 with Docker, Podman, or host virtualization, and a Helm chart covers Kubernetes, including OpenShift guidance in the docs.
  • Active and permissively licensedThe Apache-2.0 repository is written in Rust and had a push on the day this page was researched. The 0.1.x line adds a stable release cadence.

Trade-offs

  • -Early versionThe latest release is v0.1.2 and the project describes 0.1.x as introducing new isolation primitives and APIs, with an upgrade guide for the changes. Expect breaking changes as it matures.
  • -Platform limitsWindows support through WSL 2 is marked experimental. On Kubernetes, your CNI must enforce NetworkPolicy, so cluster setup matters for the isolation guarantees.
  • -You operate itUnlike a hosted sandbox service, you run and upgrade the gateway yourself, and the repository has 498 open issues at the time of writing.
  • -Anonymous telemetry on by defaultOpenShell collects anonymous operational counts. It does not collect prompts, credentials, file paths, or user content, and you can disable it with OPENSHELL_TELEMETRY_ENABLED=false or compile it out.
versus alternatives

OpenShell vs alternatives#

OpenShell vs E2B

E2B is the paid product OpenShell is linked to as an alternative. The two overlap on one job: giving an AI agent an isolated place to run code.

Where execution happens

OpenShell runs on infrastructure you control. The installer sets up a local gateway, and a Helm chart deploys the gateway to Kubernetes. With a commercial hosted sandbox service, code and context run on the vendor's infrastructure. If your agents touch private repositories or internal model endpoints, keeping execution in-house is the main reason to pick OpenShell.

Policy and credentials

OpenShell is built around a declarative YAML policy covering filesystem, network, and process rules, with credentials injected only at approved endpoints. Network rules can be changed at runtime, and risky policy changes are flagged for human review. Check the current documentation of any paid tool you compare against for how it exposes similar controls.

Cost and effort

OpenShell is free under Apache-2.0, but you run, upgrade, and monitor it yourself, and it is still at v0.1.2. A paid hosted service trades money for less operational work. Choose OpenShell when data control and auditable policy matter more than avoiding that work.

install · quick start

Quick start#

bash
Setup needs Docker, Podman, or host virtualization; the installer adds the CLI and a local gateway.
```bash
curl -LsSf https://raw.githubusercontent.com/NVIDIA/OpenShell/main/install.sh | sh
openshell sandbox create --name demo
```
tech stack · detected from GitHub

What it's built on#

Languages
GoPythonRustTypeScript
frequently asked

FAQ#

Is OpenShell really open source?

Yes. The repository is licensed under Apache-2.0, and you can run it on your own machines or in your own Kubernetes cluster.

Which agents can run inside it?

The docs name Claude Code, OpenCode, Codex, and GitHub Copilot CLI. The default sandbox image is minimal Ubuntu with no agent installed, so you install the agent you want or bring your own container image.

What do I need to run it?

Linux, macOS on Apple Silicon, or Windows with WSL 2 (experimental), plus Docker, Podman, or host virtualization. The install script sets up the CLI and a local gateway.

How does it handle credentials?

Agents never see real credentials. OpenShell adds them only to requests bound for endpoints approved by a provider profile, and attachments, rotation, and revocation update at runtime.

also worth a look

Similar open-source tools#

substrate

substrate

Kubernetes-native sandbox runtime for AI agent execution

3.9KGoApache-2.0
Omnara

Omnara

Open-source agent deployment API. Self-host or use Omnara Cloud.

2.9KGoApache-2.0
openbao

openbao

Open source secret management governed by the Linux Foundation

8.2KGoMPL-2.0
ax

ax

Declarative runtime for autonomous agent workloads

12.4KGoApache-2.0
dify

dify

Visual AI workflow builder with RAG, agents, and self-hosting

157.5KTypeScriptApache-2.0 with additional terms
security-audit-skill

security-audit-skill

Multi-phase security audits with machine-readable findings

22.9KJavaScriptMIT

Repository

Stars
10.6K
Forks
1.4K
License
Apache-2.0
Latest
v0.1.2
Last commit
today
Last verified
Sep 30, 2026
Repo
NVIDIA/OpenShell ↗

Additional details

Language
Rust
Open issues
498
Contributors
125
First release
2026

Categories

AI & Machine LearningDeveloper ToolsSecurity & MonitoringCloud & Hosting

Tags

AI AgentsSecurityKubernetesDeveloper ToolsCloud Native