Canonical
28 September 2026
Canonical announces the alpha release of Charmed OpenShell to help secure autonomous AI agent fleets
Canonical teams up with NVIDIA on the NVIDIA Open Agent Safety Platform and the Broad Availability of NVIDIA OpenShell, delivering developer-friendly packaging and enterprise-grade infrastructure.
Canonical is pleased to announce comprehensive agent-ready enterprise infrastructure for NVIDIA OpenShell which reaches broad availability today, and is part of the new NVIDIA Open Agent Safety Platform. As autonomous, self-evolving AI agents transition from experimental pilots into production operations, NVIDIA OpenShell provides an open source runtime that governs how agents execute, what resources they can access, and where inference traffic is routed. Canonical is teaming with NVIDIA to provide seamless deployment paths ranging from local developer workstations to production-scale enterprise infrastructure.
Frictionless desktop experience for developers
The OpenShell snap was released in June 2026 to give developers straightforward access to governed agent runtimes. By packaging OpenShell as a snap, Ubuntu users benefit from a one-command installation, workload confinement, and automated updates. With the OpenShell snap, users can instantly run agent sandboxes locally and test autonomous workflows, without manually configuring complex runtime dependencies.
Announcing the alpha release of Charmed OpenShell
To streamline enterprise deployment and lifecycle management, Canonical is announcing the alpha release of Charmed OpenShell. Developed in the open, Charmed OpenShell pairs OpenShell’s control plane with Canonical’s Juju operator ecosystem, providing a trusted, repeatable way to run and manage the gateway alongside the rest of the platform.
Charmed OpenShell deploys and operates the OpenShell Gateway service on Canonical Kubernetes running on MicroCloud, automatically connecting the central control plane into essential enterprise services. This enables:
- High availability (HA) and state persistence: automated integration with Charmed PostgreSQL for state store resilience and optimistic concurrency across gateway replicas
- Identity and access management: native integration with Canonical Identity Platform for OpenID Connect (OIDC) user authentication and access control
- gRPC ingress: managed Transmission Control Protocol (TCP) routing and end-to-end Transport-Layer Security (TLS) passthrough, powered by Traefik
- Centralized observability: pre-configured binding to the Canonical Observability Stack (COS), delivering native Prometheus metrics, Grafana dashboards, and Loki log aggregation
Enterprise agent infrastructure on MicroCloud
For organizations scaling agent fleets across multiple business units, Canonical provides agent-ready infrastructure through MicroCloud, our lightweight, low-touch cloud platform. To complement Charmed OpenShell, Canonical has engineered an open source LXD driver that connects the OpenShell gateway directly to MicroCloud’s virtualization layer. By using LXD’s system containers, the driver provisions isolated sandboxes at the container boundary for every agent execution. This architecture allows OpenShell to dynamically interact with MicroCloud storage, networking, and physical GPU passthrough primitives, while helping to guarantee that unverified binaries or compromised agent code remain safely contained.
“Autonomous agents represent a fundamental shift in software execution, moving from predictable scripts to self-directed systems,” said Cindy Goldberg, Vice President of Cloud and Silicon Partnerships at Canonical. “Deploying these agents at scale demands infrastructure that provides strict governance without stalling developer velocity. Through our collaboration with NVIDIA, Canonical is delivering a complete open source stack – from developer snaps to Charmed OpenShell on MicroCloud – giving organizations the safety, scale, and operational control needed to run AI agent fleets with confidence.”
Availability and resources
To learn more about NVIDIA OpenShell, visit build.nvidia.com/openshell.
To install OpenShell locally on your Ubuntu machine run sudo snap install openshell
To learn more about Charmed OpenShell consult the documentation, or contribute via the GitHub repository.
To learn more about the LXD OpenShell driver, visit the GitHub repository.
About Canonical
Canonical, the publisher of Ubuntu, provides open source security, support, and services. Our portfolio covers critical systems, from the smallest devices to the largest clouds, from the kernel to containers, from databases to AI. With customers that include top tech brands, emerging startups, governments, and home users, Canonical delivers trusted open source for everyone.
Learn more at https://canonical.com/