Skip to content

Commit f4dc6be

Browse files
authored
refactor(inference): remove managed inference routes (#3195)
* refactor(inference): remove managed inference routes Closes #3172 Remove the inference route control plane, inference.local data path, built-in router crate, and SDK surface. Move inference workloads to explicitly imported provider profiles and native endpoints, with migration cleanup and updated tests and documentation. Signed-off-by: John Myers <9696606+johntmyers@users.noreply.github.com> * fix(policy): preserve alternate upstream isolation Restore the provider policy activation guard so legacy OpenAI and Anthropic providers configured for alternate base URLs do not grant egress to the built-in public vendor endpoints. Signed-off-by: John Myers <9696606+johntmyers@users.noreply.github.com> --------- Signed-off-by: John Myers <9696606+johntmyers@users.noreply.github.com>
1 parent 7f4bd49 commit f4dc6be

142 files changed

Lines changed: 1501 additions & 19018 deletions

File tree

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

‎.agents/skills/sync-agent-infra/SKILL.md‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -45,7 +45,7 @@ Use this map when product behavior, commands, or development workflows change. I
4545
| Sandbox policy schema, presets, or enforcement behavior | `generate-sandbox-policy`, `openshell-cli` |
4646
| Supervisor middleware policy, registrations, runtime, or failure behavior | `generate-sandbox-policy`, `openshell-cli`, `debug-openshell-cluster` |
4747
| Gateway deployment, Helm, runtime drivers, or health checks | `debug-openshell-cluster`, `helm-dev-environment` |
48-
| Inference routing, providers, or `inference.local` behavior | `debug-inference`, `openshell-cli` |
48+
| Inference providers, native model endpoints, or migration from `inference.local` | `debug-inference`, `openshell-cli`, `generate-sandbox-policy` |
4949
| TUI architecture, navigation, data fetching, or UX | `tui-development` |
5050
| Release artifacts or post-publish smoke coverage | `test-release-canary` |
5151
| GitHub Actions workflows, required checks, or CI diagnostics | `watch-github-actions`; also `test-release-canary` for release smoke coverage |

‎AGENTS.md‎

Lines changed: 4 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -39,8 +39,7 @@ These pipelines connect skills into end-to-end workflows. Individual skill files
3939
| `crates/openshell-conformance-cli/` | Conformance CLI | Distributable `list` and `run` entrypoint for gateway conformance |
4040
| `crates/openshell-server/` | Gateway server | Control-plane API, sandbox lifecycle, auth boundary |
4141
| `crates/openshell-sandbox/` | Sandbox runtime | Container supervision, policy-enforced egress routing |
42-
| `crates/openshell-policy/` | Policy engine | Filesystem, network, process, and inference constraints |
43-
| `crates/openshell-router/` | Privacy router | Privacy-aware LLM routing |
42+
| `crates/openshell-policy/` | Policy engine | Filesystem, network, and process constraints |
4443
| `crates/openshell-bootstrap/` | Gateway metadata | Gateway registration metadata, auth token storage, mTLS bundle storage |
4544
| `crates/openshell-gateway-interceptors/` | Gateway interceptors | Intercepts and transforms configured gRPC requests at the gateway routing boundary |
4645
| `crates/openshell-ocsf/` | OCSF logging | OCSF v1.8.0 event types, builders, shorthand/JSONL formatters, tracing layers |
@@ -57,15 +56,14 @@ These pipelines connect skills into end-to-end workflows. Individual skill files
5756
| `crates/openshell-driver-db-credstore/` | Database credential driver | In-process `CredentialDriver` backend for gateway database credential storage |
5857
| `crates/openshell-driver-kubernetes/` | Kubernetes compute driver | In-process `ComputeDriver` backend for K8s sandbox pods |
5958
| `crates/openshell-driver-docker/` | Docker compute driver | In-process `ComputeDriver` backend for local Docker sandbox containers |
60-
| `crates/openshell-driver-mxc/` | MXC compute driver | Windows in-process `ComputeDriver` backend for MXC sandbox execution |
6159
| `crates/openshell-driver-podman/` | Podman compute driver | In-process `ComputeDriver` backend for local Podman sandbox containers |
6260
| `crates/openshell-driver-vm/` | VM compute driver | Standalone libkrun-backed `ComputeDriver` subprocess (embeds its own rootfs + runtime) |
6361
| `crates/openshell-driver-mxc/` | Microsoft MXC compute driver | In-process Windows AppContainer and isolation-session compute backend |
6462
| `crates/openshell-prover/` | Policy prover | Policy verification and proof generation |
6563
| `crates/openshell-server-macros/` | Server macros | Compile-time helpers for gateway RPC authorization |
6664
| `crates/openshell-supervisor-middleware/` | Middleware runtime | Generic middleware registry, remote service integration, and chain execution |
6765
| `crates/openshell-supervisor-middleware-builtins/` | Built-in middleware | First-party in-process middleware implementations |
68-
| `crates/openshell-supervisor-network/` | Network supervisor | Proxying, L7 enforcement, policy evaluation, and inference routing |
66+
| `crates/openshell-supervisor-network/` | Network supervisor | Proxying, L7 enforcement, policy evaluation, and provider credential injection |
6967
| `crates/openshell-supervisor-process/` | Process supervisor | Process lifecycle, namespace, and bypass monitoring |
7068
| `crates/openshell-vfio/` | VFIO support | PCI and GPU passthrough preparation and lifecycle |
7169
| `python/openshell/` | Python SDK | Python bindings and CLI packaging |
@@ -116,7 +114,7 @@ Use an OCSF builder + `ocsf_emit!()` for events that represent **observable sand
116114
- SSH authentication (accepted, denied, nonce replay)
117115
- Process lifecycle (start, exit, timeout, signal failure)
118116
- Security findings (unsafe policy, unavailable controls, replay attacks)
119-
- Configuration changes (policy load/reload, TLS setup, inference routes, settings)
117+
- Configuration changes (policy load/reload, TLS setup, provider attachments, settings)
120118
- Application lifecycle (supervisor start, SSH server ready)
121119

122120
### When to use plain tracing
@@ -138,7 +136,7 @@ Use `info!()`, `debug!()`, `warn!()` for **internal operational plumbing** that
138136
| SSH sessions | `SshActivityBuilder` | Authentication, channel operations |
139137
| Process start/stop | `ProcessActivityBuilder` | Entrypoint lifecycle, signal failures |
140138
| Security alerts | `DetectionFindingBuilder` | Nonce replay, bypass detection, unsafe policy. Dual-emit with the domain event. |
141-
| Policy/config changes | `ConfigStateChangeBuilder` | Policy load, Landlock apply, TLS setup, inference routes, settings |
139+
| Policy/config changes | `ConfigStateChangeBuilder` | Policy load, Landlock apply, TLS setup, provider attachments, settings |
142140
| Supervisor lifecycle | `AppLifecycleBuilder` | Sandbox start, SSH server ready/failed |
143141

144142
### Severity guidelines

‎CONTRIBUTING.md‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -80,7 +80,7 @@ Public skills live in `skills/` and work without an OpenShell source checkout. I
8080
| --- | --- |
8181
| `openshell-cli` | CLI usage, sandbox lifecycle, provider management, and BYOC workflows |
8282
| `debug-openshell-cluster` | Diagnose gateway deployment and health issues |
83-
| `debug-inference` | Diagnose managed, system, local, and direct external inference issues |
83+
| `debug-inference` | Diagnose attached-provider inference, native endpoints, and migration from `inference.local` |
8484
| `generate-sandbox-policy` | Generate YAML sandbox policies from requirements or API documentation |
8585

8686
Public skills use `openshell --help` for installed command syntax and published OpenShell documentation for product concepts and configuration. They must not depend on repository-relative source or documentation files.

‎Cargo.lock‎

Lines changed: 0 additions & 21 deletions
Some generated files are not rendered by default. Learn more about customizing how changed files appear on GitHub.

‎README.md‎

Lines changed: 9 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -108,15 +108,15 @@ bash examples/sandbox-policy-quickstart/demo.sh
108108
OpenShell isolates each sandbox in its own container with policy-enforced egress routing. A lightweight gateway coordinates sandbox lifecycle, and every outbound connection is intercepted by the policy engine, which does one of three things:
109109

110110
- **Allows** — the destination and binary match a policy block.
111-
- **Routes for inference** — strips caller credentials, injects backend credentials, and forwards to the managed model.
111+
- **Binds credentials to endpoints** — injects provider credentials only after policy admits a request to a profile-authorized endpoint.
112112
- **Denies** — blocks the request and logs it.
113113

114114
| Component | Role |
115115
| ------------------ | -------------------------------------------------------------------------------------------- |
116116
| **Gateway** | Control-plane API that coordinates sandbox lifecycle and acts as the auth boundary. |
117117
| **Sandbox** | Isolated runtime with container supervision and policy-enforced egress routing. |
118118
| **Policy Engine** | Enforces filesystem, network, and process constraints from application layer down to kernel. |
119-
| **Privacy Router** | Privacy-aware LLM routing that keeps sensitive context on sandbox compute. |
119+
| **Provider Access** | Profile-defined endpoints, binary policy, and endpoint-bound credential injection for model APIs and other services. |
120120

121121
OpenShell runs a gateway control plane that manages sandbox lifecycle through a configured compute driver. Supported compute platforms include Docker, Podman, MicroVM, and Kubernetes.
122122

@@ -129,14 +129,16 @@ OpenShell applies defense in depth across four policy domains:
129129
| Filesystem | Prevents reads/writes outside allowed paths. | Locked at sandbox creation. |
130130
| Network | Blocks unauthorized outbound connections. | Hot-reloadable at runtime. |
131131
| Process | Blocks privilege escalation and dangerous syscalls. | Locked at sandbox creation. |
132-
| Inference | Reroutes model API calls to controlled backends. | Hot-reloadable at runtime. |
132+
| Providers | Grants endpoint-bound credentials and network access. | Hot-reloadable at runtime. |
133133

134-
Policies are declarative YAML files. Static sections (filesystem, process) are locked at creation; dynamic sections (network, inference) can be hot-reloaded on a running sandbox with `openshell policy set`.
134+
Policies are declarative YAML files. Static sections (filesystem, process) are locked at creation; network policy and provider attachments can be updated on a running sandbox.
135135

136136
## Providers
137137

138138
Agents need credentials — API keys, tokens, service accounts. OpenShell manages these as **providers**: named credential bundles that are injected into sandboxes at creation. The CLI auto-discovers credentials for recognized agents (Claude, Codex, OpenCode, Copilot) from your shell environment, or you can create providers explicitly with `openshell provider create`. Credentials never leak into the sandbox filesystem; they are injected as environment variables at runtime.
139139

140+
Inference access uses the same provider workflow. Attach an inference-capable provider to a sandbox, call the provider's native endpoint, and select the model in the client. Provider profiles contribute the endpoint policy and bind credential placeholders to the authorized destination.
141+
140142
## GPU Support (Experimental)
141143

142144
> **Experimental** — GPU passthrough works on supported hosts but is under active development. Expect rough edges and breaking changes.
@@ -159,8 +161,8 @@ Docker-backed GPU sandboxes auto-select CDI when available and otherwise fall ba
159161
| [OpenCode](https://opencode.ai/) | [`base`](https://github.com/NVIDIA/OpenShell-Community/tree/main/sandboxes/base) | Works out of the box. Provider uses `OPENAI_API_KEY` or `OPENROUTER_API_KEY`. |
160162
| [Codex](https://developers.openai.com/codex) | [`base`](https://github.com/NVIDIA/OpenShell-Community/tree/main/sandboxes/base) | Works out of the box. Provider uses `OPENAI_API_KEY`. |
161163
| [GitHub Copilot CLI](https://docs.github.com/en/copilot/github-copilot-in-the-cli) | [`base`](https://github.com/NVIDIA/OpenShell-Community/tree/main/sandboxes/base) | Works out of the box. Provider uses `GITHUB_TOKEN` or `COPILOT_GITHUB_TOKEN`. |
162-
| [OpenClaw](https://openclaw.ai/) | [NemoClaw](https://github.com/NVIDIA/NemoClaw) | Run OpenClaw more securely inside NVIDIA OpenShell with managed inference using NemoClaw. |
163-
| [Hermes Agent](https://github.com/NousResearch/hermes-agent) | [NemoClaw](https://github.com/NVIDIA/NemoClaw) | Run Hermes Agent more securely inside NVIDIA OpenShell with managed inference using NemoClaw. |
164+
| [OpenClaw](https://openclaw.ai/) | [NemoClaw](https://github.com/NVIDIA/NemoClaw) | Run OpenClaw more securely inside NVIDIA OpenShell with the NemoClaw blueprint. |
165+
| [Hermes Agent](https://github.com/NousResearch/hermes-agent) | [NemoClaw](https://github.com/NVIDIA/NemoClaw) | Run Hermes Agent more securely inside NVIDIA OpenShell with the NemoClaw blueprint. |
164166
| [Ollama](https://ollama.com/) | [Community](https://github.com/NVIDIA/OpenShell-Community) | Launch with `openshell sandbox create --from ollama`. |
165167
| [Pi](https://pi.dev/) | [Community](https://github.com/NVIDIA/OpenShell-Community) | Launch with `openshell sandbox create --from pi`. |
166168

@@ -172,9 +174,9 @@ Docker-backed GPU sandboxes auto-select CDI when available and otherwise fall ba
172174
| `openshell sandbox connect [name]` | SSH into a running sandbox. |
173175
| `openshell sandbox list` | List all sandboxes. |
174176
| `openshell provider create --type [type] --from-existing` | Create a credential provider from env vars. |
177+
| `openshell sandbox provider attach <sandbox> <provider>` | Attach a provider to a running sandbox. |
175178
| `openshell policy set <name> --policy file.yaml` | Apply or update a policy on a running sandbox. |
176179
| `openshell policy get <name>` | Show the active policy. |
177-
| `openshell inference set --provider <p> --model <m>` | Configure the `inference.local` endpoint. |
178180
| `openshell logs [name] --tail` | Stream sandbox logs. |
179181
| `openshell term` | Launch the real-time terminal UI for debugging. |
180182

‎TESTING.md‎

Lines changed: 0 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -136,8 +136,6 @@ def test_multiply(sandbox):
136136
|---|---|---|
137137
| `sandbox_client` | session | gRPC client connected to the active gateway |
138138
| `sandbox` | function | Factory returning a `Sandbox` context manager |
139-
| `inference_client` | session | Client for managing inference routes |
140-
| `mock_inference_route` | session | Creates a mock OpenAI-protocol route for tests |
141139

142140
### Rust CLI E2E (`e2e/rust/`)
143141

0 commit comments

Comments
 (0)