On 24 September Docker released the Sandbox Kit Spec under Apache 2.0: the agent, its tools and a list of everything it wants to reach, in one ordinary container image. The standard goes under the neutral governance of the CNCF. The same day brought Cloud Sandboxes for agents that work for hours.
- A Kit is an OCI image carrying the agent, its tools and a typed list of the hosts, credentials and volumes it asks for.
- Kits were built together with AWS, Box, Datadog, Dynatrace, JFrog, Palo Alto Networks, Snyk and others.
- Cloud Sandboxes run the same microVM isolation in Docker's cloud, up to 24 hours per session, billed by the second.
Ask any team that has been running agents for a few months: what exactly does that agent have access to? According to Docker, a few months in nobody can answer.
According to Docker, the rules are scattered: a network rule here, a key there, a folder mounted in a hurry for one task. They live in terminal history and in someone's memory. Docker proposes they live in one place - inside the agent's image itself.
Why in the image
Because an image can be pinned, compared and reviewed. If the new version of an agent asks for access to one more server, it shows up as a new line in the diff that someone can refuse.
This is Docker's old idea applied to a new problem. Ten years ago they gave the image format to the Linux Foundation and it became the standard. Now they are doing the same with permissions, and again handing them to a neutral organisation.
Today's exercise is one sheet of paper on which you write what every agent you run has access to. Whoever cannot write it down is exactly the person the format is for.