we_are_coded.by CODE · The world, decoded
БГ
Docker

Docker opened a format for what an agent is allowed to do and is handing it to the CNCF

Docker Blog · event date: 24 September 2026Builders

On 24 September Docker released the Sandbox Kit Spec under Apache 2.0: the agent, its tools and a list of everything it wants to reach, in one ordinary container image. The standard goes under the neutral governance of the CNCF. The same day brought Cloud Sandboxes for agents that work for hours.

In short
  • A Kit is an OCI image carrying the agent, its tools and a typed list of the hosts, credentials and volumes it asks for.
  • Kits were built together with AWS, Box, Datadog, Dynatrace, JFrog, Palo Alto Networks, Snyk and others.
  • Cloud Sandboxes run the same microVM isolation in Docker's cloud, up to 24 hours per session, billed by the second.
Checked on1 October 2026Responsible editorTsvetelin IvanovHow we workMethod · Corrections

Ask any team that has been running agents for a few months: what exactly does that agent have access to? According to Docker, a few months in nobody can answer.

According to Docker, the rules are scattered: a network rule here, a key there, a folder mounted in a hurry for one task. They live in terminal history and in someone's memory. Docker proposes they live in one place - inside the agent's image itself.

The facts: on 24 September 2026, at the WeAreDevelopers conference, Docker announced the Docker Sandbox Kit Spec - an open specification under the Apache 2.0 licence, which it is bringing to the CNCF under neutral governance. A Kit is an ordinary OCI image carrying three things: the agent, its tools and a typed list of everything the agent asks to reach - hosts, credentials and volumes. The format uses an existing OCI extension point and is not a new artifact type; the image is built, pushed, signed and scanned like any other. Kits have been built together with AWS, Box, Datadog, Dynatrace, JFrog, NanoClaw, OpenClaw, Palo Alto Networks, Snyk and others. Docker Sandboxes is the first runtime that enforces the specification. The same day Docker launched Cloud Sandboxes - the same microVM isolation, but on Docker-managed compute, for one hour by default and up to 24 hours per session, billed per second, with one command to move between laptop and cloud.

Why in the image

Because an image can be pinned, compared and reviewed. If the new version of an agent asks for access to one more server, it shows up as a new line in the diff that someone can refuse.

This is Docker's old idea applied to a new problem. Ten years ago they gave the image format to the Linux Foundation and it became the standard. Now they are doing the same with permissions, and again handing them to a neutral organisation.

An agent's permissions have to travel with the agent, or they do not exist.

Today's exercise is one sheet of paper on which you write what every agent you run has access to. Whoever cannot write it down is exactly the person the format is for.

The visual is generated code art. No third-party images.
Follow usFacebookLinkedIn
Official primary sources
→Docker Blog - Docker Brings Sandbox Kit Spec to the CNCF, 24.09.2026→Docker Blog - Introducing Cloud Sandboxes: Start on Your Laptop, Finish in the Cloud, 24.09.2026
Original: https://wearecoded.com/en/articles/docker-sandbox-kit-spec-pravata-na-agenta.html
ShareFacebookXLinkedInTelegramWhatsApp
← Back to all news