Nvidia retires OpenShell Community image catalog as runtime goes first-party

Short names like base, ollama and pi no longer resolve; default sandbox is a bare Ubuntu 24.04 image

Nvidia has marked the OpenShell Community GitHub repository retired.

The page title is blunt: “OpenShell Community (retired).” The catalog that used to hand developers ready-made sandbox images is no longer part of the product. New work belongs on the first-party runtime, NVIDIA/OpenShell. The Community repo says it will be archived. Files stay up as examples. They are not a supported path.

That matters on the same day Nvidia put OpenShell at the center of its Open Agent Safety Platform. The runtime is the software fence around agents. The Community repo was the shortcut: pick a catalog name, get an image, a policy, sometimes an agent CLI already baked in. That shortcut is gone.

A default install now boots nvcr.io/nvidia/base/ubuntu:24.04. Minimal Ubuntu. No agent CLI in the image. No image-specific policy riding along. Bare names that openshell sandbox create --from used to expand — base, ollama, pi — no longer resolve. If a pipeline still passes those tokens, it will not get the old picture.

Nvidia’s instruction is to own the workload. Keep the Dockerfile, the OpenShell policy, the provider profiles and the build notes in a repo the team controls. Version the image. Say which OpenShell release it matches. Do not commit credentials. Profiles name the secrets; the credential backend holds the values.

Launch is explicit now. Build and push an OCI image the gateway can pull. Import provider profiles. Create provider instances. Then create the sandbox with a full image reference, a policy file and a provider, and put the start command after --. OpenShell replaces the image entrypoint with its supervisor. Skip --provider if there are no external keys. Skip --policy only if the built-in restrictive policy is enough.

The Community repo is not taking new work. No new issues. No pull requests. Docs, discussion and bugs go to NVIDIA/OpenShell. Security reports go through that project’s SECURITY.md, not a public ticket on the retired tree. Existing content remains Apache 2.0. Thirteen contributors are listed. One hundred ninety stars. Seventy-seven forks. No releases were ever published on that repo. The tree is mostly Dockerfiles, then Python, then shell.

None of that README prints a kill date for pulled images that already sit in a registry. It also does not say whether old catalog tags on Nvidia’s side will keep answering. What it does say is not to depend on this repository or its published images for new deployments.

For an engineering manager, the diligence item is simple. Search CI for --from base, --from ollama, --from pi, or any other short catalog name. Those strings are now dead aliases. Pin a registry path. Pin a digest if the auditor is picky. Move policy YAML into source control next to the Dockerfile.

For a security buyer who heard “open runtime” this morning, this is the other half. The supported boundary is OpenShell 0.1.x and, if you want silicon behind it, Sentry on BlueField-4. The community image buffet is not part of that boundary anymore. A thin Ubuntu base means the agent bits you used to inherit from ollama or pi are your image now, and so is the blast radius.

The live project has discussions, issue templates and a public roadmap. The retired one is a museum with a lock on the door. Copy what you still need. Do not file a ticket there and wait.


Subscribe
Notify of
0 Comments
Oldest
Newest Most Voted
0
Would love your thoughts, please comment.x
()
x