Build9 publishers3 min readPublished
NVIDIA keeps the out-of-band half of its agent safety platform on BlueField-4 DPUs
NVIDIA open-sourced its OpenShell agent sandbox at version 0.1.0 and put Sentry, a watchdog it says quarantines agents in milliseconds, on BlueField-4 DPUs. Operators can adopt the open sandbox by itself, but the enforcement tier on separate silicon is specified only for NVIDIA's DPUs and DOCA software.
The Engineer · Build desk

What happened
- OpenShell splits into a gateway, a per-sandbox supervisor that runs outside the agent workload, and a sandbox whose only network path goes through that supervisor.
- The supervisor can inspect HTTP, GraphQL and MCP traffic, so one policy can allow a data query and block a write through the same API.
- Sentry is built on NVIDIA's DOCA software, which it uses to inspect agent traffic, attest telemetry, verify agent identity and enforce zero-trust access policy.
- NVIDIA says OpenShell runs with minimal overhead on its Vera CPU and can be extended to third-party compute platforms from Arm and Intel.
- Cadence, Slack and Gecko Robotics are named as OpenShell users, for chip design, an on-demand agent platform and governing agents on physical robots.
Compiled by The EngineerSomething wrong?How this is made
Why it matters
- decision Teams on Arm or Intel hosts can adopt OpenShell's sandbox and policy engine now and treat Sentry as a separate decision about putting BlueField-4 DPUs in their servers.
- constraint A mixed-vendor fleet gets separate-silicon enforcement only on the machines that carry NVIDIA DPUs, because Sentry's inspection and policy enforcement are built on DOCA.
- exposure Incident plans that count on millisecond quarantine are built on NVIDIA's own number, which has not been measured independently under production load.
The OpenShell developer post shows the boundary with two commands. `openshell sandbox create --name policy-demo --no-auto-providers --policy examples/no-network.yaml` opens a shell inside a new sandbox. A curl to `https://api.github.com/zen` from that shell then fails, because the policy grants no outbound network permission [12]. Underneath, kernel controls limit which files the workload can read or change and stop it from acquiring extra system privileges [22]. Those controls stay in place when the agent starts a shell, runs generated code, launches child processes or proposes delegating to sub-agents [10].
OpenShell records its policy decisions in an Open Cybersecurity Schema Framework audit trail. When it blocks an inspected request, it can send the agent a descriptive error to help it pick its next step [11]. I think this is careful engineering. It starts from a premise stated in NVIDIA's technical blog: an agent left running on hard problems "cannot be expected to fully govern its own behavior" [19].
The same blog sets a stricter bar: "Enforcement must be out of band: The controls do not live inside, or within reach of the agent" [13]. OpenShell puts its supervisor outside the agent workload [8]. Sentry goes further. NVIDIA describes it as an isolated trust domain that agents and attackers cannot see [7]. By NVIDIA's own terms, the fullest version of its principle is the part that needs a BlueField-4 in the server [21].
The license split follows the hardware split. OpenShell is Apache 2.0 [2]. Sentry is a reference system design [1]. NVIDIA did not publish a license for Sentry, or the test conditions behind its milliseconds quarantine figure [4]. For that number to hold in a production fleet, it would need to be measured from the moment an agent crosses its boundary to the moment it stops, under real traffic. For Arm and Intel, NVIDIA's phrase is "can be extended" [5]. Until tested builds appear, I'd treat that as porting work for whoever needs it.
NVIDIA's blog calls the division shared responsibility: "Labs, enterprises, and hardware providers each own a layer, just like the cloud today" [14]. It asks for openness in one sentence: "The agent runtime and its policy language need to be open so any provider can plug in" [23]. That leaves the hardware layer to the hardware provider. In this release, that provider is NVIDIA [21].
The press release calls OpenShell "broadly available" [16], and the developer post ships it as version 0.1.0 [3]. Both are true on the same day. "Safety and security require full-stack engineering," said Jensen Huang, NVIDIA's founder and CEO [15]. NVIDIA says organizations can deploy parts of the platform to suit their own requirements [20]. An operator with no BlueField-4 hardware can take the sandbox, supervisor and policy engine today. Out-of-band enforcement on separate silicon comes only with NVIDIA DPUs [21].
What to watch
- Tested OpenShell builds or overhead figures on Arm or Intel CPUs, from NVIDIA or from those vendors.
- Whether NVIDIA releases Sentry under an open license, or shows DOCA-based enforcement consuming OpenShell policy files unchanged.
- An independent measurement of Sentry's time from boundary violation to quarantine under real traffic.