NVIDIA Developer

How to Secure & Run AI Agents with NVIDIA OpenShell

Published 2026-09-28 · Duration 5:30

Summary

NVIDIA OpenShell 0.1 provides a secure, governed runtime boundary for AI agents, preventing compromised agents from executing unauthorized actions. It allows developers to deploy agents—which are LLMs capable of tool calls and code execution—in a sandboxed environment where all components (tools, subagents, etc.) inherit consistent policy, credential, and audit controls from launch. The system supports live policy updates, delegated subagent controls, and multi-tenant deployments via Kubernetes.

Download summary

Key takeaways

  1. Runtime Boundary Enforcement

    OpenShell creates a boundary around the agent that the agent cannot escape, similar to OS-level app restrictions. This prevents malicious actions, such as an agent attempting to upload private data to a public repository, even if compromised.

  2. Policy Granularity and Control 2:00

    Policies can be configured at the level of binaries, destinations, methods, and paths. The system supports reviewing and approving network requests in real-time, ensuring the agent only performs intended actions.

  3. Multi-Tenant and Production Deployment 4:00

    For large-scale production environments, OpenShell supports Kubernetes deployment (specifically OpenShift) and utilizes multi-tenant SDKs to manage sandboxes for multiple users and business units.

Technical details

  • OpenShell Architecture 0s

    OpenShell establishes a governed runtime boundary for AI agents, ensuring that all components inherit consistent policy, credential, and audit controls.

  • Agent Harness Support 160s

    OpenShell supports various agent harnesses, including Hermes, Pi, OpenClaw, OpenCode, and proprietary harnesses like Codex or Cloud.

  • Policy Management 160s

    Policies can be defined to allow specific access (e.g., read-only access to GitHub) while blocking unauthorized actions (e.g., write access or POST requests). Policies can be reviewed and approved in real-time.

  • Deployment Models 220s

    Deployment options include single-player mode (via a curl command for dedicated VMs) and multi-tenant production environments using Kubernetes/OpenShift and the OpenShell multi-tenant Kubernetes SDKs.

  • Extensibility 260s

    The system is highly extensible, allowing integration with external identity providers (like Microsoft Entra) and enabling custom policy parsers, compute drivers, and credential stores via interceptors and middleware.

Mentioned resources

Channel & topics

Watch on YouTube · Back to latest

This independent, AI-assisted summary is provided for commentary and informational purposes. It may contain errors or omit important context. Please watch the original video for the creator's complete presentation. Video, thumbnail, and related copyrights belong to their respective owners.