# How to Secure & Run AI Agents with NVIDIA OpenShell

## Executive summary

NVIDIA OpenShell 0.1 provides a secure, governed runtime boundary for AI agents, preventing compromised agents from executing unauthorized actions. It allows developers to deploy agents—which are LLMs capable of tool calls and code execution—in a sandboxed environment where all components (tools, subagents, etc.) inherit consistent policy, credential, and audit controls from launch. The system supports live policy updates, delegated subagent controls, and multi-tenant deployments via Kubernetes.

## Key takeaways

- Runtime Boundary Enforcement: OpenShell creates a boundary around the agent that the agent cannot escape, similar to OS-level app restrictions. This prevents malicious actions, such as an agent attempting to upload private data to a public repository, even if compromised.
- Policy Granularity and Control: Policies can be configured at the level of binaries, destinations, methods, and paths. The system supports reviewing and approving network requests in real-time, ensuring the agent only performs intended actions.
- Multi-Tenant and Production Deployment: For large-scale production environments, OpenShell supports Kubernetes deployment (specifically OpenShift) and utilizes multi-tenant SDKs to manage sandboxes for multiple users and business units.

## Technical details

- OpenShell Architecture: OpenShell establishes a governed runtime boundary for AI agents, ensuring that all components inherit consistent policy, credential, and audit controls.
- Agent Harness Support: OpenShell supports various agent harnesses, including Hermes, Pi, OpenClaw, OpenCode, and proprietary harnesses like Codex or Cloud.
- Policy Management: Policies can be defined to allow specific access (e.g., read-only access to GitHub) while blocking unauthorized actions (e.g., write access or POST requests). Policies can be reviewed and approved in real-time.
- Deployment Models: Deployment options include single-player mode (via a curl command for dedicated VMs) and multi-tenant production environments using Kubernetes/OpenShift and the OpenShell multi-tenant Kubernetes SDKs.
- Extensibility: The system is highly extensible, allowing integration with external identity providers (like Microsoft Entra) and enabling custom policy parsers, compute drivers, and credential stores via interceptors and middleware.

## Practical implications

- Provides a robust pattern for adding sandboxed execution and policy enforcement to existing agent stacks.
- Enables live policy updates without restarting the sandbox.
- Supports delegated-agent controls, where child runtimes inherit and cannot exceed the parent's defined limits.
- Facilitates centralized logging and audit records for understanding all allowed and denied actions.

## Topics

AI Agents, Sandboxing, Policy Enforcement, Kubernetes, LLMs, Security, NVIDIA Developer Tech blog

Source: https://www.youtube.com/watch?v=GYYP-eW58ug
