openshell CLI. The workload sandbox does not receive your Blaxel key, gateway key, or model-provider credentials.
Prerequisites
- A Blaxel account and workspace with access to the
landlock,tun, andiptableskernel variants - A service-account API key for the workspace
- The
blCLI, logged in to your workspace - Go
1.25or newer - The GitHub CLI and Git
main from the NVIDIA dev release. The verified integration uses OpenShell commit 08548713c, release 0.0.117-dev.281, the openshell.compute.v1 compute-driver protocol, and Blaxel Go SDK v0.27.2.
1. Configure the deployment
Clone the Blaxel OpenShell integration repository:.env and set:
BL_WORKSPACEto your Blaxel workspace nameBL_ENVto the target Blaxel environmentBL_REGIONto the region where the sandboxes runBL_API_KEYto the workspace service-account API key
2. Deploy the control plane
Build OpenShell and create the Blaxel control sandbox:- downloads OpenShell
mainfrom NVIDIA’sdevrelease and checks its checksums - builds the Blaxel compute driver and WebSocket tunnel
- creates the control sandbox with
tunandiptablesenabled - generates the gateway public key infrastructure
- starts the gateway, driver, ingress tunnel, CLAT, and DNS forwarder
- downloads the CLI client bundle to
~/.openshell-blaxel/mtls
make deploy again updates the binaries in place and restarts the gateway and driver.
How Blaxel networking supports OpenShell
How Blaxel networking supports OpenShell
Blaxel sandboxes are IPv6-only with NAT64/DNS64, and only HTTPS leaves the platform. OpenShell’s policy DNS currently resolves A records only, so the control sandbox runs a 464XLAT CLAT with
tayga and a DNS-over-HTTPS forwarder.Blaxel exposes HTTPS and WebSocket ingress through /port/N. The CLI and Sandbox Protocol therefore use multiplexed WebSockets, with TLS preserved end to end.The upstream change in NVIDIA/OpenShell pull request #3702, tracked by issue #3716, removes the need for the CLAT after it is merged.3. Connect the OpenShell CLI
Start the local tunnel and register the CLI with the gateway:4. Verify the deployment
Run the end-to-end test suite:landlock kernel variant with Linux 6.18 and Landlock ABI v7. The agent runs as UID 1500 with no capabilities, no_new_privs, Landlock, seccomp, and a network namespace that only contains loopback. Policy-approved egress passes through its supervisor.
5. Create and enter a workload sandbox
Create a sandbox nameddev and keep its main process running:
-- is the sandbox’s main process. sleep infinity keeps the sandbox alive while interactive shells connect and disconnect.
6. Apply a read-only network policy
Export the sandbox’s base policy:/usr/bin/curl to send read-only REST requests to api.github.com:
curl https://api.github.com/zen now succeeds. A POST request is denied at HTTP layer 7, and hosts that are not listed in the policy do not resolve.
OpenShell
main currently emits policy get --base output without a trailing newline. The blank line before network_policies keeps the appended YAML valid.7. Inspect and manage the deployment
Read the sandbox’s OCSF allow and deny audit trail:--apply to a cleanup command after reviewing its exact plan.
Redeploying restarts the gateway and driver. A workload sandbox pins its first supervisor, so a sandbox that was running before a redeploy needs a new generation. If it appears as Stopped, start it again:
8. Delete the resources
Delete the workload sandbox:Resources
OpenShell on Blaxel
Review the integration source, design guide, security boundaries, failure handling, and teardown procedures.
NVIDIA OpenShell
Learn about OpenShell policies, architecture, and runtime isolation.
Blaxel sandboxes
Learn how to create and operate isolated microVM compute environments.