Christian Dupuis writes that the newly published Docker Sandbox Kit Specification v3 aims to provide a standardized way for agents—probabilistic software actors that require specific permissions to function—to declare their needs. Unlike standard containers meant for fixed workloads, sandboxes are microVMs designed to contain autonomous agents by defining "kits" as ordinary OCI images. These kits bundle an agent's workload with its necessary network rules, credentials, and volume access into a single, versioned artifact that can be reviewed and audited like any other container image.
- A Kit is implemented as an ordinary OCI image using the `vnd.docker.sandbox.kit.descriptor` annotation.
- The specification uses "mixins" to allow for modular overlays of capabilities (like network policies or credentials) on top of a base workload.
- Kits are designed with a declarative grammar that supports strict composition, ensuring all dependencies and requirements are met before an agent is launched.
- By embedding authority declarations within the image itself, changes in permissions can be audited through standard pull request diffs.
A curated guide to code sandboxing solutions, covering technologies like MicroVMs, application kernels, language runtimes, and containerization. It provides a feature matrix, in-depth platform profiles (e2b, Daytona, microsandbox, WebContainers, Replit, Cloudflare Workers, Fly.io, Kata Containers), and a decision framework for choosing the right sandboxing solution based on security, performance, workload type, and hosting preferences.