Docker Donates Sandbox Kit Spec to CNCF for AI Agents
Docker has submitted its Sandbox Kit Specification to the CNCF, standardizing how developers package AI agent permissions and guardrails directly inside portable OCI images.

Docker announced at the WeAreDevelopers conference that it is bringing its Sandbox Kit Specification to the Cloud Native Computing Foundation (CNCF). Now at version 3, the Apache 2.0-licensed specification aims to standardize how developers manage the security permissions of autonomous AI agents. Currently, agents like Claude Code and Codex require broad access to local files, APIs, and credentials, but these privileges are typically scattered across shell histories and configuration dashboards rather than stored in a unified, auditable format.
The Sandbox Kit solves this fragmentation by packaging an AI agent, its tools, and its required permissions into a standard Open Container Initiative (OCI) image. In version 3, the kit is no longer a custom artifact type. Instead, it uses a single declaration in the manifest, allowing developers to build, pull, scan, and sign kits using standard tools like 'docker buildx build' and 'docker pull'. Permissions are defined as typed, versioned capabilities, such as network policies or credential requirements. For example, a kit can permit traffic to a specific API while explicitly denying destructive actions, with proxy-managed credentials keeping sensitive tokens outside the agent's sandbox.
During execution, a host runtime decides whether to grant the requested permissions. The launch process combines a workload kit containing the root filesystem with mixin overlays, which are resolved using a dependency graph. If a required permission cannot be met, the runtime blocks the launch. Docker Sandboxes, which run agents inside isolated microVMs, serves as the initial conforming runtime. Docker developed the specification alongside industry partners including AWS, Box, Datadog, Dynatrace, JFrog, NanoClaw, OpenClaw, Palo Alto Networks, and Snyk.
For software engineers, the specification introduces a command-line tool called 'sbx' to run and test kits locally. While existing registries and security scanners can process these images without modification, developers must learn the new descriptor grammar and capability semantics. Because Docker Sandboxes is currently the only conforming runtime, true cross-runtime portability remains unproven. However, standardizing these guardrails ensures that as the ecosystem matures, security policies can be versioned and pinned alongside the agent's code.
This is our own summary of reporting by InfoQ AI



