Canonical ships Charmed OpenShell alpha for agent fleets
Canonical has packaged NVIDIA's OpenShell runtime as a snap and pushed out an alpha of Charmed OpenShell to run governed AI agent fleets on Kubernetes and MicroCloud.

Canonical has packaged NVIDIA's OpenShell agent runtime as a snap and released an alpha of Charmed OpenShell, an orchestration layer that puts the gatekeeper for autonomous agents under the same management as the rest of an enterprise's Kubernetes estate. The work sits inside NVIDIA's new Open Agent Safety Platform, and Canonical's pitch is that governance should look like ordinary platform engineering rather than a model-level promise.
What OpenShell governs
OpenShell is an open source runtime that decides how an agent executes, which resources it can reach and where its inference traffic is routed. On a developer workstation, Canonical now ships it as a snap, installed with a single command and updated automatically, which gives developers a confined sandbox to test autonomous workflows without hand-building runtime dependencies.
The interesting part is what Canonical wrapped around it. Charmed OpenShell deploys and operates the OpenShell Gateway service on Kubernetes and wires the control plane into the services an enterprise already runs, rather than asking a security team to bolt them on afterwards. That means high availability and state persistence across gateway replicas, OpenID Connect authentication through the Canonical Identity Platform, managed TCP routing with end-to-end TLS passthrough powered by Traefik, and telemetry pre-bound to the Canonical Observability Stack for Prometheus metrics, Grafana dashboards and Loki log aggregation.
Sandboxes down to the container boundary
For organisations scaling fleets of agents across several business units, Canonical has also built an open source LXD driver that connects the OpenShell gateway to MicroCloud, its lightweight private cloud. Each agent execution gets an isolated sandbox at the container boundary, and OpenShell can reach MicroCloud's storage, networking and physical GPU passthrough primitives while keeping unverified binaries and compromised agent code contained. That containment claim is the one to watch: the failure mode everyone fears with autonomous agents is not a bad answer, it is code that runs with the permissions of whatever it was handed.
Cindy Goldberg, Canonical's vice president of Cloud and Silicon Partnerships, framed the shift as one from predictable scripts to self-directed systems, and argued that deploying agents at scale needs strict governance that does not stall developer velocity. The company describes the result as a complete open source stack, from a developer snap up to a charmed gateway running on MicroCloud. Anyone wanting to try it on Ubuntu can install the runtime with a single snap command.
Our opinion
Agent governance has spent a year being sold as a prompt-level promise, which is a strange place to put a security control when the agent can also open a shell. Canonical's contribution is deliberately boring: identity, network policy, TLS, logs and metrics, all in the layers enterprises already audit. If agent fleets are going to be real, they will be governed like workloads, and this is what governing them like workloads looks like.
The caveat is written on the tin. NVIDIA's runtime is the piece at broad availability; the Charmed orchestration around it is an alpha, and an alpha is not what a bank's platform team deploys into a regulated cluster on a Tuesday. Canonical is also betting that customers want to run agent sandboxes on their own infrastructure rather than hand the problem to a hosted platform. That bet looks reasonable for anyone already running Kubernetes and MicroCloud, and considerably less appealing for the much larger group that has not yet decided it needs an agent fleet at all.