How to Secure & Run AI Agents with NVIDIA OpenShell
NVIDIA OpenShell 0.1 provides a secure, governed runtime boundary for AI agents, preventing compromised agents from executing unauthorized actions. It allows developers to deploy agents—which are LLMs capable of tool calls and code execution—in a sandboxed environment where all components (tools, subagents, etc.) inherit consistent policy, credential, and audit controls from launch. The system supports live policy updates, delegated subagent controls, and multi-tenant deployments via Kubernetes.
Key takeaways
-
Runtime Boundary Enforcement
OpenShell creates a boundary around the agent that the agent cannot escape, similar to OS-level app restrictions. This prevents malicious actions, such as an agent attempting to upload private data to a public repository, even if compromised.
-
Policy Granularity and Control
2:00
Policies can be configured at the level of binaries, destinations, methods, and paths. The system supports reviewing and approving network requests in real-time, ensuring the agent only performs intended actions.
-
Multi-Tenant and Production Deployment
4:00
For large-scale production environments, OpenShell supports Kubernetes deployment (specifically OpenShift) and utilizes multi-tenant SDKs to manage sandboxes for multiple users and business units.