Solutions  ·  2026-09-28

Docker launches Cloud Sandboxes and open-sources Sandbox Kit Spec (to CNCF) for secure AI agent execution

SolutionsMedium impactGlobal
On Sept 24-25, 2026 Docker announced Docker Cloud Sandboxes — microVM-isolated, policy-enforced cloud execution for AI agents (with local-to-cloud handoff) — plus the Apache 2.0 Sandbox Kit Spec: OCI images that package an agent, its tools, and a typed list of permitted hosts/credentials/volumes so agent permissions travel with the artifact. Docker is contributing the spec to the CNCF, with AWS, Box, Datadog, Dynatrace, JFrog, Palo Alto Networks, and Snyk already publishing Kits.
This is a meaningful answer to the agent-permissions fragmentation problem: a neutral, OCI-based standard for declaring what an agent may reach, usable by registries/scanners/signers, comparable and enforceable across runtimes — directly relevant to agent least-privilege and supply-chain security.
Platform engineering and appsec teams standardizing agent isolation and permission portability should evaluate Docker Sandboxes and the open Kit spec; developers running coding agents can adopt Kits now, and runtime vendors should track CNCF governance.
Docker launches Cloud Sandboxes (GlobeNewswire)Docker Brings Sandbox Kit Spec to the CNCF (linux.com)
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →