Devops iconDevopsSep 28, 2026 ~3 min source read

Docker publishes an open Sandbox Kit spec to declare AI agent permissions in OCI images

Docker released a specification that packages AI agents, their tools and explicit access requests as OCI images so teams and runtimes can inspect and gate network, credential and storage permissions before an agent runs. Docker plans to submit the spec to CNCF for neutral governance.

Docker Introduces Open Sandbox Kit Spec for AI Agent Permissions

Share this story

Send the public story page.

Useful takeaways from this story.

Sandbox Kit is an Apache 2.0 specification for packaging an AI agent or supporting components as OCI images with declared network, credential, volume and capability requests.

Because access declarations live inside the OCI image, teams can review changes to an agent’s requested authority and gate updates tied to image digests.

Docker will contribute the spec to the Cloud Native Computing Foundation to encourage cross-vendor implementation beyond Docker Sandboxes.

# What Docker announced

Docker introduced an open Sandbox Kit specification that packages an AI agent, its tools and the access it requests as OCI images. The spec is published under the Apache 2.0 license and is intended as a common format that sandbox runtimes and developers can use to describe the environment and authorities an agent needs.

# Why this matters

AI agents act differently than conventional workloads: they may install dependencies, run code, call external services and probe their environment to find capabilities they can use. That behavior makes it harder to rely on container boundaries alone. By declaring requested hosts, credentials, volumes and other capabilities inside the image, the Sandbox Kit format gives teams a way to review and approve what an agent will be allowed to do before it runs.

# How the spec works in practice

  • Kits are packaged as OCI images with descriptors that list network hosts, credentials, volumes and capabilities the agent or supporting component requests.
  • Using OCI images lets teams build, store, sign and scan Kits with the same tooling they already use for containers.
  • Pinning a Kit to an image digest ties the agent's code and its access declaration together, so any change in requested authority is visible during updates.
  • Runtimes can gate updates that expand access, stopping them until reviewed and approved.

Docker President and COO Mark Cavage presented the specification at the WeAreDevelopers North America conference. He used a demo where an agent running in a container accessed a host secret by leveraging a mounted Docker socket. Cavage distinguished between containers (an execution mechanism) and containment (controls around what an agent is allowed to do), arguing that agents require explicit, reviewable declarations of authority rather than relying solely on container isolation.

# Adoption and governance plans

# Practical implications for teams

  • Image signing and OCI scanning workflows apply directly to Sandbox Kits, enabling existing build-and-release controls to cover agents and tools.
  • Pinning Kits by digest makes it easier to detect and block unauthorized expansions of access during updates.

# Short summary

More context around this story.

AI бЂ”бЂЉбЂєбЂёбЂ•бЂЉбЂ¬бЂЂбЂ­бЂЇ бЂЎбЂ™бЂјбЂ”бЂєбЂ†бЂЇбЂ¶бЂё бЂњбЂ±бЂ·бЂњбЂ¬бЂ”бЂЉбЂєбЂё
Medium iconMediumSep 5, 2026

AI бЂ”бЂЉбЂєбЂёбЂ•бЂЉбЂ¬бЂЂбЂ­бЂЇ бЂЎбЂ™бЂјбЂ”бЂєбЂ†бЂЇбЂ¶бЂё бЂњбЂ±бЂ·бЂњбЂ¬бЂ”бЂЉбЂєбЂё

AI (Artificial Intelligence) နည်းပညာက အá€á€¯á€¡á€á€»á€­á€”်မှာ နေရာá€á€­á€¯á€„်းမှာ ရှိနေပါပြီዠဒါပေမဲ့ “AI ကို ဘယ်ကနေ စလေ့လာရမလဲአအမြန်ဆုံး á€á€á€ºá€™á€¼á€±á€¬á€€á€ºá€¡á€±á€¬á€„်â

Loading more related stories...

Keep reading in the app

Open the app view to save this story, compare related coverage, and continue from the same source.

Open in app