OpenShell v0.0.43 🛠️ bidirectional TTY streaming 🔒 OIDC auth in the TUI 🧩 HTTPS and mTLS decoupled 📦 TOML gateway config (RFC 0003) 🖥️ sandboxes boot from ext4 disks 🛡️ DNS removed from sandbox mapper to block exfiltration Authentication, streaming, and sandbox isolation improvements. https://t.co/vtEWZ79Cwi
NVIDIA Hardens OpenShell Agent Runtime With OIDC and DNS Exfiltration Blocks
- Authentication
- OIDC, mTLS, and HTTPS
- Configuration format
- TOML (RFC 0003)
- Sandbox storage
- ext4 root disks
- Security hardening
- DNS-based exfiltration blocking
- Interactive support
- Bidirectional TTY streaming
As organizations move toward production-grade agentic engineering, security remains the primary hurdle for autonomous systems. By decoupling HTTPS from mTLS and removing DNS resolution from the sandbox mapper, NVIDIA is addressing specific exfiltration risks. These changes ensure that even if an agent is compromised, it cannot easily leak sensitive data through unauthorized network lookups.
You can now boot sandboxes from ext4 root disks and manage gateway settings via a new TOML-based configuration format. The update also restores sandboxes automatically after a gateway restart, improving reliability for long-running tasks. OpenShell v0.0.43 is available now on GitHub for developers building isolated enterprise agent environments.
Still wondering? A few quick answers below.






