{"name":"shoreguard: Manage NVIDIA OpenShell Agent Sandboxes","description":"ShoreGuard adds a web UI, REST API, and Terraform workflow for managing NVIDIA OpenShell sandboxes, policies, and routed inference. It suits teams operating multiple gateways that need centralized access controls and auditability.","github":"https://github.com/FloHofstetter/shoreguard","url":"https://osrepos.com/repo/flohofstetter-shoreguard","source":"osrepos.com","sourceDescription":"This repository profile is provided by osrepos.com, an open source repository discovery platform.","repositoryProfile":"https://osrepos.com/repo/flohofstetter-shoreguard","generatedFor":"open source discovery and AI-assisted research","markdown":"https://osrepos.com/repo/flohofstetter-shoreguard.md","json":"https://osrepos.com/repo/flohofstetter-shoreguard.json","topics":["python","ai-agents","security","api","agent-sandbox-management","inference-routing"],"keywords":["python","ai-agents","security","api","agent-sandbox-management","inference-routing"],"stars":null,"summary":"ShoreGuard adds a web UI, REST API, and Terraform workflow for managing NVIDIA OpenShell sandboxes, policies, and routed inference. It suits teams operating multiple gateways that need centralized access controls and auditability.","content":"## Overview\n\nShoreGuard is a Python management plane for NVIDIA OpenShell, which provides hardened runtime environments for AI agents. It gives operators a centralized way to manage sandboxes, policies, gateways, and inference routing instead of relying on OpenShell’s CLI alone.\n\nIt is aimed at teams running agents across multiple OpenShell gateways. ShoreGuard keeps provider credentials out of agent code by routing inference through OpenShell, while exposing management through a web interface, REST API, and Terraform.\n\n## Key Features\n\n- Create and manage sandboxes across multiple OpenShell gateways.\n- Edit network, filesystem, and process policies with revision history.\n- Review agent requests for endpoint access through approval workflows.\n- Pin policies during incidents or change freezes.\n- Verify selected policy properties using Z3-based checks.\n- Export and apply policies through a YAML-based GitOps workflow.\n- Track changes in an audit log and expose Prometheus metrics.\n- Integrate with Terraform, Paperclip, OpenClaw, and signed webhooks.\n\n## Use Cases\n\n- Platform teams managing development, staging, and production OpenShell gateways from one interface.\n- Security operators who need approval controls, policy history, and an audit trail for agent sandbox changes.\n- Infrastructure teams applying sandbox policies through version-controlled YAML and CI workflows.\n- Teams hosting agent workloads that need inference credentials kept outside the sandbox.\n\n## Our Take\n\nShoreGuard offers a broad management layer for OpenShell, but its quiet recent activity and highly concentrated contributions make adoption a measured choice.\n\n**Good fit if:**\n- You already use NVIDIA OpenShell and need multi-gateway management beyond its CLI.\n- Your team can run Python 3.14 or newer and operate the Docker-based services.\n- You value centralized policy management, approvals, and auditability, and can assess the project’s current maintenance pace.\n\n**Look elsewhere if:**\n- You need a management tool for runtimes other than OpenShell.\n- Your environment cannot support the stated Python version or Docker-based deployment.\n- You require evidence of active issue and pull-request handling: none were closed or merged in the measured recent period.\n\n## Project Health\n\n| Signal | Value |\n|---|---|\n| Status | **Quiet**: no commits in the last 90 days |\n| Last commit | 2026-08-01 (2 months ago) |\n| Commits, last 90 days | 0 |\n| Releases, last 12 months | 16 (latest v0.40.0, 2026-06-20) |\n| Contributors | 2 (top contributor: 97% of commits) |\n| Issues closed, last 90 days | 0 |\n| Pull requests merged, last 90 days | 0 |\n| Project age | 7 months |\n\nChecked on 2026-10-08 with the GitHub API.\n\n## Project Facts\n\n- Language: Python\n- License: Apache-2.0\n- Stars: 4\n- Forks: 2\n- Topics: ai-agents, control-plane, fastapi, nvidia, openshell, sandbox, security\n- Archived: no\n\n## What You Need\n\nDetected in the repository:\n\n- Python >=3.14 (from pyproject.toml)\n- A Dockerfile, so it can run in a container; a Compose file sets up the related services\n- A Helm chart for Kubernetes\n- A test suite and automated checks on GitHub Actions\n\n## Getting Started\n\nFor local development, install and run ShoreGuard:\n\n```bash\npip install shoreguard\nshoreguard --local --no-auth\n```\n\nThen open `http://localhost:8888`. See the [README](https://github.com/FloHofstetter/shoreguard) for Docker Compose deployment and setup details.\n\n## License in Plain Words\n\n**Apache-2.0** (permissive).\n\n- Commercial use: yes\n- Modify and redistribute: yes\n- You must keep: the license, the NOTICE file and a note of your changes\n- Share your changes: no\n- Includes an explicit patent grant from the contributors\n\nA summary, not legal advice: the LICENSE file is what applies.\n\n## Alternatives\n\n- [agent-sandbox](https://osrepos.com/repo/agent-sandbox-agent-sandbox): Agent-Sandbox creates isolated agent environments on Kubernetes with a REST API and MCP server, rather than managing NVIDIA OpenShell gateways, policies, and routed inference.\n- [CubeSandbox](https://osrepos.com/repo/tencentcloud-cubesandbox): CubeSandbox runs agent workloads in hardware-isolated microVMs with snapshots and network controls, rather than providing centralized management for NVIDIA OpenShell.\n\n| Project | Language | License | Stars | Status |\n|---|---|---|---|---|\n| **shoreguard** | Python | Apache-2.0 | 4 | Quiet |\n| [agent-sandbox](https://osrepos.com/repo/agent-sandbox-agent-sandbox) | Go | Apache-2.0 | 218 | Active |\n| [CubeSandbox](https://osrepos.com/repo/tencentcloud-cubesandbox) | Go | NOASSERTION | 12.8k | Active |\n\n## Considerations\n\nThe project is marked quiet, with no commits in the measured last 90 days and no issues closed or pull requests merged in that period. It has had regular releases over the past year, but most contributions come from one of its two contributors, which creates a maintainer-concentration risk. The README also says hardened sandbox deployment through the gRPC API is blocked by OpenShell API limitations, and routed inference for the Paperclip adapter remains in progress. The project requires Python 3.14 or newer; its production setup uses Docker Compose and PostgreSQL. It is licensed under Apache-2.0.","metrics":{"detailViews":2,"githubClicks":0},"dates":{"published":null,"modified":"2026-10-08T20:46:28.000Z"}}