← All stories
● Covered by 1 source · 1 reportMedium impact1 neutral

Docker Contributes Sandbox Kit Spec to CNCF for AI Agent Permission Management

🔄 Updated 4h ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • Docker contributed Sandbox Kit Spec v3 to CNCF.
  • Packages AI agent permissions as OCI images.
  • Specifies agent access to hosts, credentials, volumes.
  • Allows standard OCI tools for building, pulling, scanning.

Standardizing AI Agent Permissions

Docker announced the contribution of its Sandbox Kit Specification to the Cloud Native Computing Foundation (CNCF). The goal of this move is to standardize the packaging and management of permissions for AI agents, making them as portable as the agents themselves. The Apache 2.0 licensed specification, now in version 3, integrates an agent, its tools, and a typed list of requested hosts, credentials, and volumes into a standard OCI image.

Addressing Fragmentation in Agent Access Management

AI agents often require access to system resources, such as installing packages, calling APIs, and using credentials. Currently, these grants (like bind mounts, broad tokens, and firewall rules) are typically managed in disparate locations like shell history or dashboards, rather than in reviewable artifacts. Docker argues that the Sandbox Kit Specification, by leveraging OCI, provides a unified approach to prevent each runtime vendor from developing their own proprietary solutions for managing agent access.

Technical Details of Sandbox Kit v3

In version 3, a Kit is no longer a separate artifact type; it lacks a custom media type and sidecar file. The manifest includes a specific declaration: `vnd.docker.sandbox.kit.descriptor`. This integration means Kits can be built using `docker buildx build`, pulled with `docker pull`, and scanned, signed, or used in `FROM` instructions, ensuring content and permissions are pinned together by the digest. Declarations are typed and versioned capabilities, such as `com.docker.sandbox/network-policy@2` and `com.docker.sandbox/credential@1`. For example, a Kit can allow access to `api.github.com` but deny `DELETE` operations on `/repos/**`, with deny rules taking precedence. Credentials can be proxy-managed, where a conforming runtime injects actual tokens into requests to named domains, while only a sentinel value exists within the sandbox.

Runtime Conformance and Launch Process

A Kit only requests permissions; the host environment determines whether to grant them. Without a conforming runtime, the annotations within the Kit are inert. If a required request cannot be fulfilled, the launch of the agent is refused. Docker Sandboxes, which execute agents in microVMs with their own kernels, is the initial conforming runtime for this specification. The launch process combines a workload Kit, providing the root filesystem, with multiple mixin overlays. Mixins are ordered based on a `provides`/`requires` dependency graph. Resolution fails if a `requires` is unmet or if duplicate names are provided by different Kits. Overlapping declarations are reconciled, with network rules being unioned, and incompatible declarations resulting in errors.

Ensuring Integrity and Conformance

Each descriptor in the specification reduces to a normalized set of grants. Runtimes that manage updates can record this set and prevent any new version that widens the grants, including those that remove a deny rule. Docker states that two conformance suites are provided with the specification: one for Kit artifacts and another for runtimes, to ensure consistent implementation and behavior.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~34 min · 27 stories · Oct 02

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Reporting from

Docker has contributed its Sandbox Kit Specification to the CNCF, aiming to standardize how AI agent permissions are packaged and managed using OCI images. This specification allows developers to define and bundle an AI agent's access rights, tools, and resource requests within a standard OCI image, addressing the current fragmentation in managing agent capabilities.