Docker Cloud Sandboxes Provide a Consistent Sandbox Abstraction across Laptop and Cloud
Docker introduced Cloud Sandboxes, hosted execution environments for running AI coding agents on Docker-managed infrastructure, InfoQ reported on Sep 26, 2026. The platform is built on hardware-enforced microVM isolation and provides a consistent execution environment and unified CLI workflows for moving workloads from local machines to the cloud.
According to Docker, Cloud Sandboxes are an evolution of Docker Sandboxes, introduced earlier this year to give coding agents local microVM environments in which to operate autonomously and safely. Docker says developers are increasingly running multiple long-horizon tasks in parallel, creating demand for persistent, scalable execution environments beyond the local machine.
With Cloud Sandboxes, developers can move a sandbox between local and cloud execution with one command, which Docker says makes it possible to run a dozen agents at once for five, ten, or 21 hours each without watching any of them. Cloud Sandboxes use the same isolation model as local Docker Sandboxes and are managed through the same CLI. Docker describes use cases including starting a task locally and moving it to the cloud when it needs more resources, handing a task off before leaving for the day, and parallelizing dozens of tasks each in its own isolated cloud sandbox. Docker says the transfer command captures the sandbox's filesystem and recreates it on the other side.
Alongside Cloud Sandboxes, Docker released several kits, described as pre-configured, pre-built sandboxes defined according to the Docker Sandbox Kit Specification. In the Kits v3 specification, kits are no longer treated as a separate artifact and are packaged as standard OCI images, allowing them to be used like any other Docker image, including with build and pull, and to serve as a base for more complex kits.
Deutsche Bank lead devops engineer Florin Lungu said he finds it interesting that the innovation allows safe, autonomous coding in microVM environments, enhancing flexibility in workflows. Reddit user CircumspectCapybara said sandboxing addresses only part of the issue, arguing useful agent workloads need to connect sandboxed agents to limited external services such as real libraries or artifacts pulled from PyPI, Docker Hub or Hugging Face, creating a potential attack surface even when the agent remains contained. Hacker News reader ongedierte echoed the concern, arguing traditional sandboxes are not the correct abstraction and that harnesses based on object capabilities will be the way forward.
Based on reporting from the original publisher. Visit the source for full context and later updates.
Publisher excerpt
Docker Cloud Sandboxes provide secure, hosted execution environments for running AI coding agents on Docker-managed infrastructure. Built on hardware-enforced microVM isolation, the platform provides a consistent execution environment and unified CLI workflows for seamlessly moving workloads from local machines to the cloud. By Sergio De Simone