Urgent.News

What's breaking now, across thousands of outlets.

AI

Docker Sandbox Kit Spec: Packaging AI Agent Permissions as OCI Images

Docker has announced that it is bringing the Sandbox Kit Specification to the CNCF, aiming to make what an AI agent may access as portable as the agent itself. By Claudio Masolo

Docker has introduced a specification called Sandbox Kit Specification, aiming to make AI agent permissions portable like the agents themselves. This Apache 2.0 v3 spec, unveiled at WeAreDevelopers on September 24, packages agents, their tools, and a list of host, credential, and volume requests into an ordinary OCI image. The primary goal is to prevent the fragmentation that OCI was created to avoid, as every runtime vendor might otherwise devise its own approach.

In this specification, a Kit is no longer a separate artifact type. Instead, it has a single declaration: vnd.docker.sandbox.kit.descriptor. This allows Kits to be built with docker buildx build, pulled with docker pull, scanned, signed, or used in a FROM statement. The Kit's content and permissions are tied together through its digest pinning.

The spec introduces typed and versioned capabilities, such as com.docker.sandbox/network-policy@2 and com.docker.sandbox/credential@1. For instance, a Kit could allow access to api.github.com but deny DELETE on /repos**. Credentials can be proxy-managed, meaning a conforming runtime injects the actual token into requests to specific domains, while only a sentinel value remains inside the sandbox.

A Kit only specifies permissions; the host decides. If a required request cannot be fulfilled, the launch is refused. Docker Sandboxes, the first conforming runtime, runs agents in microVMs with their own kernel. A launch combines one workload Kit, containing the root filesystem, with any number of mixin overlays. Mixins are ordered based on a dependency graph, and if a required provision is not met or two Kits provide the same name, resolution fails.

Every descriptor reduces to a normalized set of grants. A runtime that controls updates can record this set and prevent any version that widens it, even if it removes a deny rule. Docker provides two conformance suites: one for Kit artifacts and one for runtimes. Docker built Kits using AWS, Box, Datadog, Dynatrace, JFrog, NanoClaw, OpenClaw, Palo Alto Networks, and Snyk, among other companies.

Docker sees this as analogous to their donation of the image format and runc, which led to OCI. The CNCF CTO, Chris Aniszczyk, welcomed the move, emphasizing that standards enable ecosystems to move quickly without fragmentation. Docker's delivery of Sandbox Kits as standard OCI images provides an open and repeatable way to package AI agents, their tools, and guardrails as a single artifact.

However, the spec hasn't been accepted into a CNCF program or assigned a maturity level. Docker currently maintains the specification, and feedback regarding any kit or runtime duties that cannot currently be expressed is encouraged.

Written by urgent.news from InfoQ's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at infoq.com →

More in AI

More from Friday 2 October →