Dev News Daily ENDE

Docker takes its Sandbox Kit spec for agent permissions to the CNCF

Docker has announced that it is bringing the Sandbox Kit Specification to the Cloud Native Computing Foundation, InfoQ reports. The Apache 2.0 specification, now at version 3, packages an AI agent, its tools and a typed list of the hosts, credentials and volumes it requests into an ordinary OCI image. Docker announced the move at WeAreDevelopers on 24 September.

The problem Docker describes is that agents such as Claude Code and Codex install packages, call APIs and use credentials on a user's behalf, and the grants that make them useful, from bind mounts to broad tokens and opened firewall rules, usually live in shell history and dashboards rather than in a reviewable artifact. In v3 a Kit is no longer a separate artifact type: the image manifest carries a single descriptor, so a Kit can be built with docker buildx build, pulled, scanned, signed or used in a FROM. Pinning the digest pins content and permissions together.

Permissions are typed, versioned capabilities, such as a network policy or a credential. In the spec's GitHub CLI example the Kit allows api.github.com but denies DELETE on /repos/**, and deny wins. Credentials can be proxy-managed, so the real token is injected into requests to named domains while only a placeholder exists inside the sandbox. A Kit only requests; the host decides, and a launch is refused if a required request cannot be met. Every descriptor reduces to a normalised set of grants, so a runtime can stop an update that widens permissions, including one that removes a deny rule.

Docker says it built Kits with AWS, Box, Datadog, Dynatrace, JFrog, Palo Alto Networks and Snyk, among others, and CNCF CTO Chris Aniszczyk welcomed the move. InfoQ notes the limits: the posts do not say whether the spec has been accepted into a CNCF programme or at which level, enforcement depends entirely on the runtime, and Docker Sandboxes, which runs agents in microVMs, is so far the only conforming implementation, so portability across runtimes has not been shown.

Docker takes its Sandbox Kit spec for agent permissions to the CNCF
Docker takes its Sandbox Kit spec for agent permissions to the CNCF — Dev News Daily

Why it matters

Agent permissions are today mostly a matter of what someone typed once. Putting them in a signed, diffable image layer makes them reviewable in the same pipeline as the code, but the promise of portability rests on other runtimes adopting the spec.