Example of Creating a Sandbox without Network Access (Unverified on Physical Hardware)

AI・機械学習カテゴリを表すパンダのイラスト AI & Machine Learning

This article is a technical explanation and implementation example generated using AI. Although the published code and procedures are structured based on primary sources, the author has not verified the operation on physical hardware. Operation may vary depending on the environment and version.

NVIDIA OpenShell 0.1.0 is an open-source runtime designed to securely manage AI agent execution privileges and data access. This article outlines its main features and components based on official information.

Objective

Allowing AI agents to perform autonomous tasks with broad privileges introduces risks of unintended modifications and data leaks. By utilizing NVIDIA OpenShell, you can establish a mechanism at the runtime level to restrict API operations, protect credentials, and enforce policies without rewriting the agent's own code.

Prerequisites and Notes

  • The content explained in this article is based on primary sources, and operation has not been verified on physical hardware.

  • NVIDIA OpenShell 0.1.0 functions by combining sandbox execution, controlled service access, credential management, and formal policy analysis.

  • Organizations such as Cadence, Slack, and Gecko Robotics adopt OpenShell for governance in chip design, enterprise automation, and physical robotics.

Key Components of OpenShell

OpenShell primarily includes three components to manage agent fleets and sandboxes.

flowchart TD
    A[OpenShell Gateway] --> B[OpenShell Supervisor]
    B --> C[OpenShell Sandbox]
    C -->|カーネルレベルの制御| D[ファイルシステム・プロセス]
    B -->|トラフィック検査| E[外部サービス]
  • OpenShell Gateway: Manages the lifecycle and policies of multiple sandboxes.

  • OpenShell Supervisor: Pairs with each sandbox, operating outside the agent workload to validate outbound requests against policies.

  • OpenShell Sandbox: Executes workloads using kernel-level filesystem and process controls, having no network path other than through the supervisor.

Key Features of OpenShell 0.1.0

This section organizes the key features described in the primary sources and explains how they are useful.

Introduced FeaturesOverview and Role
Multi-Tenant Platform SupportOperate agent services for multiple teams or customers with isolated workspaces, permissions, and service access on a shared infrastructure.
Formal Policy VerificationShow human and AI reviewers whether requested permissions remain within defined security boundaries or where they deviate from them.
Extensible Security and GovernanceConnect third-party security services, governance systems, and custom checks to enforcement mechanisms outside the agent workload.
Credential-Protected Service AccessUtilize authenticated services by binding to authorized requests while keeping actual credentials outside the agent workload.
CPU and GPU ExecutionExecute experiments and data processing on CPU or GPU across container, VM, and Kubernetes environments.

Policy Enforcement and Log Verification Mechanisms

OpenShell allows you to define and enforce network access and policies for sandboxes in YAML format. For example, if you create a sandbox with outbound networking completely restricted and attempt to access a public endpoint, the policy will cause the request to fail.

# ネットワークアクセスを許可しないサンドボックスの作成例(実機未確認)

openshell sandbox create --name policy-demo \
  --no-auto-providers \
  --policy examples/no-network.yaml

By checking the logs from the host terminal, you can understand which program made the request and why it was blocked. Additionally, by applying policies such as a read-only GitHub REST API policy, you can control the same API to allow reads while blocking writes.

Credential Protection and Policy Advisor

If an AI agent requires a new data source or service during operation and the request is blocked by a policy, OpenShell records that denial.

  • Policy Advisor: When enabled, the agent can propose narrowly scoped network or file policy modifications. This proposal requires human review by default and cannot be approved by the agent itself.

  • Credential Isolation: Provider profiles define credentials, endpoints, and permitted programs. Actual credentials are kept external to the agent and are injected only into requests destined for authorized endpoints.

Formal Policy Verification and Deployment

To verify that policies do not leave unintended pathways, OpenShell's policy prover uses formal logic. This verifies whether modeled permissions remain within boundaries or can identify actions that exceed those boundaries.

During development, you can start with a local sandbox, and when scaling to serve multiple users, you can utilize the SDK following the workspace and access guides. Compute drivers support integration with Docker, Podman, MicroVMs, and Kubernetes.

Conclusion

  • NVIDIA OpenShell 0.1.0 is an open-source framework that enforces permissions on the runtime side without requiring any rewrites of AI agent code.

  • Through the integration of gateways, supervisors, and sandboxes, it achieves kernel-level control and traffic inspection.

  • The procedures and commands introduced in this article are based on primary sources, and behaviors or prerequisites may vary depending on the operating environment and version. When actually deploying and verifying, always check the official documentation and the latest migration notes.

References

Document information

Article title
Example of Creating a Sandbox without Network Access (Unverified on Physical Hardware)
Published
Updated
Source
https://papanda925.com/?p=17950&lang=en

License: Text and original figures for which this site holds the relevant rights are available under CC BY 4.0 , unless otherwise noted. This article may include content created or edited with generative AI. If code has a separate license notice or a linked GitHub repository license, that license takes precedence for the code. Quotations, third-party materials, images, and trademarks are excluded from this license. Usage policy

Copied title and URL