Breakpoint

Docker engineering blog

Trust Docker for the agents you don’t
Docker introduces Cloud Sandboxes, which run AI agents in isolated microVMs and let developers move long-running work between local and cloud environments. The post also details the open Sandbox Kit specification, runtime-enforced permissions, auditability, and Docker’s plan to bring the format to CNCF governance.
From Dockerfile to Kit: the Docker Sandboxes Kit Specification
Docker’s Sandbox Kit Specification v3 packages an AI agent’s workload, network policies, credentials, volumes, and lifecycle requirements into a pinnable OCI image. The post explains capability requests, deterministic mixin composition, conformance, and update-gating rules that make agent authority reviewable and reproducible across runtimes.
Introducing Cloud Sandboxes: Start on Your Laptop, Finish in the Cloud
Docker introduces Cloud Sandboxes, extending its microVM-based environments for coding agents to Docker-managed compute. Developers can move sandboxes between laptops and the cloud with one command, run long-lived tasks in parallel, and apply isolated secrets, MCP integrations, and network policies.
Manufacturing Trust for AI Agents | Docker’s WeAreDevelopers Keynote
Docker presents Sandboxes, Kits, and Cloud Sandboxes as infrastructure for running AI agents with stronger isolation and reproducible authority. The keynote covers microVM-based boundaries, policy-controlled access to files, networks, and secrets, OCI-based packaging, and moving agent work from laptops to the cloud.
Docker and CNCF partner on an open spec for agent permissions
Docker is proposing the Sandbox Kit Spec as an open, OCI-based standard for packaging an AI agent, its tools, and required permissions in a single portable image. The specification brings agent authority under CNCF governance so registries, scanners, signing tools, and conforming runtimes can inspect and enforce capability changes consistently.
Meet the Ecosystem: Partners and Customers at WeAreDevelopers with Docker
Docker previews its partner and customer sessions at WeAreDevelopers World Congress North America, covering agent security, deployment, observability, payments, memory, and code verification. The post highlights speakers, session topics, and opportunities to see ecosystem technologies in action at the Docker Pavilion.
6 Benefits of Sandbox Environments (and How Docker Sandboxes Delivers Them)
The post explains six benefits of sandbox environments for autonomous AI agents, including microVM isolation, runtime network and filesystem controls, credential protection, disposability, and reproducible Linux workspaces. It also describes how Docker Sandboxes applies these mechanisms consistently across coding agents to reduce blast radius and support governance.
YOLO Mode: Agent Autonomy Without the Guardrails
The post explains YOLO mode, where AI coding agents automatically approve actions without confirmation, and examines the risks of host-level access, prompt injection, credential exposure, and destructive commands. It recommends running autonomous agents in isolated, disposable environments with scoped networking, filesystems, and credentials to contain the blast radius.
Building Reproducible AI Evaluation Workflows with Docker Sandboxes
Jennifer Kohl explains how Docker Sandboxes and the SBX AI Evaluation Kit make AI evaluation workflows reproducible by isolating execution environments and preserving structured runtime evidence. The workflow separates evaluation definitions from execution, records commands and outcomes, and supports repeatable evaluation suites.
Below the Harness: Governing a Multi-Model, Multi-Harness World
Docker argues that multi-model, multi-harness AI agents require a security boundary below the agent harness. It applies the confused-deputy model to agent runtimes, advocating centralized enforcement for code execution, tool calls, credentials, spend, and auditing across an organization’s agent fleet.
Secure by default is your only way forward
Docker argues that AI agents require secure-by-default foundations and a dedicated execution boundary. It presents hardened, minimal base images, signed SBOMs and provenance, MicroVM-based sandboxes, trusted MCP servers, and gateway-enforced authentication and authorization as controls for reducing supply-chain and agent-related risk.
Moving from Minimus to Docker Hardened Images
Docker outlines how Minimus customers can migrate before the registry shuts down on October 22, 2026, while images remain maintained. It presents Docker Hardened Images as a drop-in alternative and highlights catalog coverage, CVE reduction, SBOMs, provenance, signatures, and available migration support.
MinIO End of Life: How to Stay Patched and Audit-Ready with Docker ELS
Docker explains how its Extended Lifecycle Support program keeps archived MinIO and other end-of-life components patched for up to five years. The post covers backported dependency fixes, hardened images, CVE response SLAs, and audit evidence including SBOMs, VEX statements, and SLSA provenance.
Running AI agents in GitHub Actions with Docker Sandboxes
The post demonstrates how to run GitHub Agentic Workflows inside Docker Sandboxes, using a microVM, private Docker daemon, network allowlists, and restricted pull-request outputs to contain autonomous coding agents. It walks through a Java and PostgreSQL Testcontainers example that detects and fixes a case-insensitive email bug in an isolated CI workflow.
Docker Verified Publisher Applications Are Now Self-Serve
Docker makes applications for its Verified Publisher program self-serve, adding plan choices while retaining manual review. The post explains how verification, ranking, and analytics work, and recommends pairing publisher trust with digest pinning, signature and provenance checks, and CVE review.
Coding Agent Horror Stories: The Command You Already Approved
Jennifer Kohl examines CVE-2026-22708 in Cursor, showing how shell built-ins can silently alter environment variables so an apparently safe approved command executes attacker-controlled code. The post explains the attack’s limits and Docker Sandboxes’ isolation, network-policy, credential-forwarding, workspace, and audit-log trade-offs.
17,600 Actions: Agent Security Is a Systems Problem
Jin Kim argues that securing AI agents requires systems-level controls rather than human approval of every action. Drawing on the OpenAI/Hugging Face incident, the post explains task-scoped identities, hardened isolation, capability-based tool access, provenance checks, cross-system observability, and machine-speed containment as defenses against high-volume agent activity.
Make zero CVEs your new default
Docker outlines updates to its software supply-chain security portfolio, including source-built hardened images and packages, extended lifecycle patching, scalable customization, and hardened Helm charts and MCP servers. It also details portable Rego policies in Docker Scout for enforcing security controls across CI and developer machines.
Reproducible ESP32 Firmware Development with Docker and Docker Sandboxes
The article presents a reproducible ESP32 firmware workflow using pinned Espressif Docker images, compiler caching, stable device mappings, and CI integration. It also explains how Docker Sandboxes can isolate AI coding agents while enabling controlled hardware-in-the-loop testing through RFC2217 serial bridges.