NVIDIA / NVIDIA/OpenShell

Support running Middleware in Sandboxes

Open
#2,684 2 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

state:stale
Dominant language
Rust
Stars
8.7k
Forks
1.3k
Avg merge
2d 11h
Merged PRs (30d)
253

Description

Problem Statement

OpenShell users should be able to run a middleware service in a sandbox so they can apply an OpenShell policy to the middleware service as well.

Proposed Design

Need a design proposal.

Alternatives Considered

Running middleware unsandboxed is an option, but it requires users to trust their middleware services.

Agent Investigation

No response

Checklist
  • I've reviewed existing issues and the architecture docs
  • This is a design proposal, not a "please build this" request

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start with the architecture documentation referenced in the checklist and trace how OpenShell currently runs middleware and applies policies. Produce a design proposal for running middleware inside a sandbox, including the trust and policy implications; the work is done when the proposal is specific enough to guide implementation.

Written by the indexing model from the issue text.

Assessment

Tech stack
rust
Domain
security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Active
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.