From Dockerfile to Kit: the Docker Sandboxes Kit Specification
Docker published the Sandbox Kit Specification v3, an open‑source Apache 2.0 spec that defines a Kit as an OCI image describing which agent runs, its permissions and resources. The spec aims to make agent sandboxes reproducible across runtimes, reducing ad‑hoc configuration and improving isolation for AI‑driven workloads.
Docker published the Sandbox Kit Specification v3, an open-source Apache 2.0 specification that defines a Kit as an OCI image. This format declares which agent runs, along with its required permissions and resources, allowing the configuration to travel directly with the agent. Two kinds of Kits exist, consisting of workloads that supply the root filesystem and mixins that act as overlays for configurations. The specification aims to make agent sandboxes reproducible across runtimes by replacing ad-hoc configurations stored in shell history or memory with a structured format. By packaging declarations directly into an OCI image, teams can review, version, and distribute sandbox requirements using standard container tooling. This approach establishes clear boundaries for probabilistic agents while managing credentials and network access through explicit runtime enforcement. The source text does not clarify how every potential third-party runtime will implement the required enforcement mechanisms outside of Docker Sandboxes. It remains uncertain how broader industry adoption will handle conflicting dependency graphs when multiple mixins are combined. The documentation also omits details on how long-term maintenance of these versioned specifications will evolve across different operating environments.