AI product Open source
Docker Sandboxes is a Docker-developed proprietary tool for running AI coding agents and other workloads inside isolated microVMs on a local machine or Docker-managed cloud infrastructure. Each sandbox has its own kernel and filesystem, controls access to the host filesystem, network, and tools, provides a private Docker daemon for test containers, uses secret placeholders, blocks network access by default, and records an audit trail. It supports agents including Claude Code, Codex, Gemini CLI, and OpenCode, with configurable network and filesystem rules, read-only mounts, MCP catalogs, and policy-based governance controls. It is distributed as the `sbx` command-line tool for macOS, Windows, and Linux, with stable, release-candidate, and nightly builds.
6 uses taken from transcripts — each links to the moment in the video.
A sandboxing solution for running AI models and tools more securely. The video says containers alone are not safe enough and highlights Docker Sandboxes as a successful example of cloud security isolation.
Docker Sandboxes run coding agents such as Claude Code inside isolated microVMs with their own kernel, file system, and network. They let agents operate in YOLO mode while restricting access to the host machine, configuring network policies and secrets, and disposing of the environment when finished.
A microVM-based sandbox that runs agents, shells, code, Python jobs, and web servers with an isolated kernel and filesystem, secret placeholders, default-deny networking, audit trails, and configurable governance controls.
Runs agents and other workloads inside isolated microVMs with a separate kernel, filesystem isolation, secret placeholders, default-deny networking, audit trails, and configurable access controls.
Documentation for installing and using Docker Sandboxes, including its sandboxing and agent-governance capabilities.
The GitHub releases page for SBX, Docker's command-line binary for creating and running microVM sandboxes.
3 in the library.