OpenShell explained: where an AI agent is allowed to act
OpenShell quickstart: inspect the installer and first sandbox
Create a disposable local sandbox without mistaking CLI installation for agent setup
What you will learn
- Check the host first
- Create an empty first sandbox
- Keep the first test observable
Before you start
- One disposable workload and a supported compute runtime
- Authority to inspect policy and provider configuration
Turn the documented controls into a small reviewable operational report
Key takeaways
- A newly created sandbox does not include an agent.
- Windows WSL 2 support is marked experimental in the pinned matrix.
- Installer success and gateway readiness are separate checks.
Check the host first
The pinned support matrix lists Linux on amd64 or arm64 and Apple Silicon with Docker Desktop as supported host paths; Windows with WSL 2 is experimental. A container or virtualization runtime is also required.
Read the installer at the same revision you plan to use, then select a stable release artifact for production. A `curl | sh` command changes local software and may retrieve more files; this article does not execute it.
Create an empty first sandbox
The documented quickstart installs OpenShell and runs `openshell sandbox create --name demo`. The default sandbox image is a minimal Ubuntu environment with no AI agent installed. A successful create checks lifecycle plumbing, not agent behavior.
Inspect the resulting sandbox and base versus effective policy before adding a provider. The project’s first-agent tutorial adds OpenCode and an inference provider later, which is a different test with external credentials and network access.
Keep the first test observable
Record CLI and gateway versions, host runtime, sandbox image and creation result. If it fails, identify whether the installer, gateway startup, compute driver or policy selection was the first failing step.
Delete the disposable sandbox after recording findings, but confirm the command’s scope before running it. The series offers a test plan; it has not installed OpenShell or created a sandbox.
Decision guide
| Criterion | Option A | Option B |
|---|---|---|
| Best when | You need predictable behavior and easy auditing | You need adaptive optimization and have reliable telemetry |
| Main risk | May leave performance on the table | Can become difficult to explain or debug |
Implementation steps
- 1
Check the support matrix and inspect the installer.
- 2
Create a named disposable sandbox using a pinned release.
- 3
Inspect its selected policy and record creation or failure evidence.
Copy-ready example
openshell sandbox create --name demo
openshell policy get demo --base
openshell policy get demo --fullFrequently asked questions
Does the quickstart run an AI model?
No. The default image contains no agent; follow the separate first-agent guide if you need one.
Should I use a floating dev build in production?
The support matrix recommends stable releases for production deployments.
Sources
- OpenShell / README.mdSource checked 2026-10-04
- OpenShell / docs/about/installation.mdxSource checked 2026-10-04
- OpenShell / docs/about/support-matrix.mdxSource checked 2026-10-04
- OpenShell / docs/how-it-works/policies/default-policy.mdxSource checked 2026-10-04