
OpenShell is a self-hosted runtime for teams running autonomous AI agents that need access to files, APIs and credentials. It runs agents in sandboxes with kernel-level isolation and explicit access policies. It's open source under Apache 2.0 and supports Linux and macOS on Apple Silicon, with Docker, Podman or host virtualization.
It works with coding assistants including Claude Code, OpenCode, Codex and GitHub Copilot CLI. Teams can give each sandbox access to selected files and approved network destinations while blocking privilege escalation and dangerous system calls. Agents receive credential placeholders; OpenShell supplies the real credentials only to requests bound for authorized endpoints.
Policies are reviewable YAML files that teams can keep in version control. Formal verification checks proposed changes for risky additions, such as access to another host with credentials or permission to call another API method. Those changes wait for human review. Network rules and credential attachments can change at runtime, while file and process restrictions stay fixed for the sandbox's lifetime.
Teams can connect sandboxes to self-hosted or private model endpoints. The runtime can run locally, and its gateway can also run on Kubernetes. The default workload uses Ubuntu, with support for custom containerized environments.
OpenShell collects anonymous operational telemetry by default, which teams can disable. It excludes prompts, user content, credentials, file paths, hostnames and model or provider names.
Claim this page with an email at docs.nvidia.com. OpenShell gets the verified badge, and you can upgrade the listing to be featured on localhosted. Proud to be listed? Put our badge on your site.
Want more people to find OpenShell?Promote it
Something wrong or outdated on this page?
12.8KUpdated 4 days agoApache-2.0
Docker#Agent Skills#Code execution#Distributed execution
AX is Google's self-hosted AI agent orchestrator for teams running autonomous workloads on a Kubernetes cluster. It uses Agent Substrate to isolate agent execution and manages the workspaces and model settings each task needs. The project is open source under Apache 2.0.
814Updated 15 hours ago
macOS · Linux · Docker · Web#Agent Client Protocol#Code execution#Git integration
Helix is a paid, self-hosted platform for engineering teams running coding agents in parallel. Each task gets an isolated Linux desktop with an editor, browser and terminal, so agents can build and test applications while teammates watch or take control through their browsers.
201Updated 3 months agoMIT
macOS · Linux#Distributed execution#Guardrails#Human approval
42.5KUpdated 12 hours agoApache-2.0
Docker · Web#Guardrails#Human approval#LLM tracing
1.1KUpdated 16 hours agoMIT
iOS · Android · Docker · Web#Code execution#Distributed execution#Git integration
Optio is a self-hosted AI agent orchestration platform for teams running coding and automation work on their own Kubernetes clusters or paired machines. Its pull request workflow follows a ticket through coding, CI, review, and merge, resuming the agent when checks fail, conflicts arise, or a reviewer asks for changes. When checks pass and approval arrives, it squash-merges the PR and closes the issue.
4.7KUpdated 22 hours agoApache-2.0
Linux#Agent Client Protocol#Code execution#Human approval
claudectl is a local dashboard and supervisor for developers running several Claude Code agents on macOS or Linux. It brings session activity, approvals and spending into one terminal view, with an optional local LLM that makes decisions based on your preferences. It's open source under the MIT license.
Agno is a Python framework and runtime for developers building customer-facing or internal AI agents. You can run its agent platform locally with Docker, on your own servers or in your cloud. The open-source framework uses the Apache 2.0 license, and the platform keeps sessions, memory, knowledge and traces in your database.
Rivet AgentOS gives AI agents an isolated working environment inside an existing backend process. It's for developers building agent applications who want to run workloads on their own hardware or servers without managing a separate virtual machine for every agent. The runtime uses WebAssembly and V8 isolates and runs on standard Linux infrastructure without nested virtualization.