Post

Docker Sandbox Kit Spec: Packaging AI Agent Permissions as OCI Images

Docker’s Sandbox Kit proposal packages an agent, its tools, and its requested permissions in a standard OCI image, so teams can review and version the requests alongside the workload. The typed capabilities cover resources such as network hosts, credentials, and volumes; Docker says Kits can use ordinary image build, pull, signing, and scanning workflows, and that it is bringing the Apache-2.0 specification to CNCF governance.

The important limit: a Kit declares requested authority; it does not enforce it by itself. The host decides what to grant, and enforcement requires a conforming runtime. Docker Sandboxes is the first such runtime, according to Docker. InfoQ reports that the v3 spec also defines conformance suites and rules for combining workload images with mixins. InfoQ has no reader-comment section, so there are no source-site reactions to summarize.