AivexaNewsSearch
AI news for builders and product teamsChecked every hour

Docker Sandbox Kit Spec: Packaging AI Agent Permissions as OCI Images

Collected Oct 2, 2026

Docker has announced that it is bringing the Sandbox Kit Specification to the CNCF, aiming to make what an AI agent may access as portable as the agent itself. The Apache 2.0 spec, now at v3, packages an agent, its tools, and a typed list of the hosts, credentials, and volumes it requests into an ordinary OCI image. Docker announced the move at WeAreDevelopers on September 24.

In v3, a Kit is no longer its own artifact type, with no custom media type and no sidecar file. The manifest has one declaration: vnd.docker.sandbox.kit.descriptor. A Kit can be built with docker buildx build, pulled with docker pull, and scanned, signed, or used in a FROM. Pinning the digest pins content and permissions together.

Declarations are typed and versioned capabilities, for example com.docker.sandbox/network-policy@2 and com.docker.sandbox/credential@1. In the spec's GitHub CLI example, the Kit allows api.github.com but denies DELETE on /repos/**, since deny wins. Credentials can be proxy-managed, with a conforming runtime injecting the real token into requests to named domains while only a sentinel value exists inside the sandbox.

A Kit only requests permissions; the host decides. Without a conforming runtime, the annotation is inert, and if a required request cannot be satisfied, the launch is refused. Docker Sandboxes, which run agents in microVMs with their own kernel, is the first conforming runtime.

A launch combines one workload Kit, supplying the root filesystem, with any number of mixin overlays. Mixins are ordered by the provides/requires dependency graph rather than flag order. Resolution fails if a requires is unmet or if two Kits provide the same name. Overlapping declarations reconcile, with network rules unioned, and incompatible ones are errors.

Every descriptor reduces to a normalized set of grants. A runtime that gates updates can record that set and stop any version that widens it, including one that removes a deny rule. Docker says two conformance suites ship with the spec, one for Kit artifacts and one for runtimes.

Docker says it built Kits with AWS, Box, Datadog, Dynatrace, JFrog, NanoClaw, OpenClaw, Palo Alto Networks, and Snyk, among others. CNCF CTO Chris Aniszczyk welcomed the move, saying standards let an ecosystem move fast without fragmenting and that Docker is giving the industry an open, repeatable way to package an AI agent, its tools, and its guardrails as one artifact. The posts do not say whether the spec has been accepted into a CNCF program or which maturity level it would enter.

The project is hosted at the docker/sandbox-kit-spec repository, with examples testable using the sbx CLI. Existing registries, scanners, and signing tools handle Kits without modification, but the descriptor grammar and per-capability semantics are new and will require learning. Enforcement depends entirely on the runtime; since Docker Sandboxes is currently the only conforming implementation, portability across different runtimes has not yet been demonstrated. Until governance changes, Docker continues to maintain the specification and encourages feedback regarding any kit or runtime duties that cannot currently be expressed.

Read at InfoQ · AI, ML & Data Engineering

Based on reporting from the original publisher. Visit the source for full context and later updates.

Publisher excerpt

Docker has announced that it is bringing the Sandbox Kit Specification to the CNCF, aiming to make what an AI agent may access as portable as the agent itself. By Claudio Masolo