Docker introduces Cloud Sandboxes, which run AI agents in isolated microVMs and let developers move long-running work between local and cloud environments. The post also details the open Sandbox Kit specification, runtime-enforced permissions, auditability, and Docker’s plan to bring the format to CNCF governance.
Docker engineering blog
Docker’s Sandbox Kit Specification v3 packages an AI agent’s workload, network policies, credentials, volumes, and lifecycle requirements into a pinnable OCI image. The post explains capability requests, deterministic mixin composition, conformance, and update-gating rules that make agent authority reviewable and reproducible across runtimes.
Docker introduces Cloud Sandboxes, extending its microVM-based environments for coding agents to Docker-managed compute. Developers can move sandboxes between laptops and the cloud with one command, run long-lived tasks in parallel, and apply isolated secrets, MCP integrations, and network policies.
Docker presents Sandboxes, Kits, and Cloud Sandboxes as infrastructure for running AI agents with stronger isolation and reproducible authority. The keynote covers microVM-based boundaries, policy-controlled access to files, networks, and secrets, OCI-based packaging, and moving agent work from laptops to the cloud.
Docker is proposing the Sandbox Kit Spec as an open, OCI-based standard for packaging an AI agent, its tools, and required permissions in a single portable image. The specification brings agent authority under CNCF governance so registries, scanners, signing tools, and conforming runtimes can inspect and enforce capability changes consistently.
Docker previews its partner and customer sessions at WeAreDevelopers World Congress North America, covering agent security, deployment, observability, payments, memory, and code verification. The post highlights speakers, session topics, and opportunities to see ecosystem technologies in action at the Docker Pavilion.
The post explains six benefits of sandbox environments for autonomous AI agents, including microVM isolation, runtime network and filesystem controls, credential protection, disposability, and reproducible Linux workspaces. It also describes how Docker Sandboxes applies these mechanisms consistently across coding agents to reduce blast radius and support governance.
The post explains YOLO mode, where AI coding agents automatically approve actions without confirmation, and examines the risks of host-level access, prompt injection, credential exposure, and destructive commands. It recommends running autonomous agents in isolated, disposable environments with scoped networking, filesystems, and credentials to contain the blast radius.
Jennifer Kohl explains how Docker Sandboxes and the SBX AI Evaluation Kit make AI evaluation workflows reproducible by isolating execution environments and preserving structured runtime evidence. The workflow separates evaluation definitions from execution, records commands and outcomes, and supports repeatable evaluation suites.
Docker argues that multi-model, multi-harness AI agents require a security boundary below the agent harness. It applies the confused-deputy model to agent runtimes, advocating centralized enforcement for code execution, tool calls, credentials, spend, and auditing across an organization’s agent fleet.
Docker argues that AI agents require secure-by-default foundations and a dedicated execution boundary. It presents hardened, minimal base images, signed SBOMs and provenance, MicroVM-based sandboxes, trusted MCP servers, and gateway-enforced authentication and authorization as controls for reducing supply-chain and agent-related risk.
Docker outlines how Minimus customers can migrate before the registry shuts down on October 22, 2026, while images remain maintained. It presents Docker Hardened Images as a drop-in alternative and highlights catalog coverage, CVE reduction, SBOMs, provenance, signatures, and available migration support.
Docker explains how its Extended Lifecycle Support program keeps archived MinIO and other end-of-life components patched for up to five years. The post covers backported dependency fixes, hardened images, CVE response SLAs, and audit evidence including SBOMs, VEX statements, and SLSA provenance.
The post demonstrates how to run GitHub Agentic Workflows inside Docker Sandboxes, using a microVM, private Docker daemon, network allowlists, and restricted pull-request outputs to contain autonomous coding agents. It walks through a Java and PostgreSQL Testcontainers example that detects and fixes a case-insensitive email bug in an isolated CI workflow.
Docker makes applications for its Verified Publisher program self-serve, adding plan choices while retaining manual review. The post explains how verification, ranking, and analytics work, and recommends pairing publisher trust with digest pinning, signature and provenance checks, and CVE review.
Jennifer Kohl examines CVE-2026-22708 in Cursor, showing how shell built-ins can silently alter environment variables so an apparently safe approved command executes attacker-controlled code. The post explains the attack’s limits and Docker Sandboxes’ isolation, network-policy, credential-forwarding, workspace, and audit-log trade-offs.
Jin Kim argues that securing AI agents requires systems-level controls rather than human approval of every action. Drawing on the OpenAI/Hugging Face incident, the post explains task-scoped identities, hardened isolation, capability-based tool access, provenance checks, cross-system observability, and machine-speed containment as defenses against high-volume agent activity.
Docker outlines updates to its software supply-chain security portfolio, including source-built hardened images and packages, extended lifecycle patching, scalable customization, and hardened Helm charts and MCP servers. It also details portable Rego policies in Docker Scout for enforcing security controls across CI and developer machines.
The article presents a reproducible ESP32 firmware workflow using pinned Espressif Docker images, compiler caching, stable device mappings, and CI integration. It also explains how Docker Sandboxes can isolate AI coding agents while enabling controlled hardware-in-the-loop testing through RFC2217 serial bridges.
Docker VMM is now available in public beta for Mac and Windows. Learn what this means for performance, stability, and governance and how to try it yourself.