Bản viết lại dựa trên nguồn: https://www.docker.com/blog/docker-sandbox-kit-spec-cncf/
Docker Brings Sandbox Kit Spec to the CNCF | Docker Skip to content Products AI and Agents Docker Sandboxes New Isolated environments for coding agents AI Governance New Govern agents and Claws across every team MCP Enterprise Gateway Connect and manage MCP tools Gordon Your AI Agent across Docker Docker Model Runner Local-first LLM inference made easy Application Security Docker Hardened Images Ship with secure, enterprise-ready images Docker Scout Simplify the software supply chain Application Development Docker Desktop Containerize your applications Docker Hub Discover and share container images Docker Offload Break free of local constraints Support Developers Documentation Find guides for Docker products Getting Started Learn the Docker basics Resources Search a library of helpful materials Training Skill up your Docker knowledge Extensions SDK Create and share your own extensions Community Connect with other Docker developers Open Source Explore open source projects Preview Program Help shape the future of Docker Customer Stories Get inspired with customer stories Get the latest Docker news Pricing Yearly Monthly Docker Personal $0 $0 For individual developers who need the essential tools to build and deploy containers. Get started Get started Docker Pro $11 $9 per user/month For individual professionals who require more advanced features and additional resources. Buy now Buy now MOST POPULAR Docker Team $16 $15 per user/month For small teams that need collaborative tools to make working together more efficient. Buy now Buy now Docker Business $24 $24 per user/month For enterprises desiring robust security, control, and compliance features. Buy now Buy now Contact sales Contact sales Docker Hardened Images (DHI) Secure, minimal container images for every team, free with enterprise features, if needed. Start Free Trial BlogDocs Search Sign In Contact Sales Toggle menu Docker and CNCF partner on an open spec for agent permissions Posted Sep 24, 2026 Eli Aleyner and Srini Sekaran Docker and CNCF: Making what an agent may do as portable as the agent itself Ten years ago, the software industry faced a choice. Every vendor could ship its own image format and its own runtime, and developers would have to pick a side. Or the industry could agree on one artifact. The second option won. Docker donated its image format and the Runc runtime to the Linux Foundation, and the Open Container Initiative (OCI) formed around them. Today, a Docker image built anywhere can run anywhere. The format is the backbone of the cloud native ecosystem and a de facto standard. Now, we see a similar problem forming around agents. There is no shared format for what an agent is allowed to do. We are proposing the same kind of answer: one artifact, built on OCI, governed in the open. The same problem, for agents Containers were built for immutable software. The image is the application. If you want to change it, you rebuild it, and it behaves the same way everywhere. That’s why a container image describes how software is built and says nothing about what it may do once it runs. For a web service, that was fine. It got a network and a port, and that was enough. Agents are mutable by definition. Claude Code and Codex install packages, call APIs, and use credentials on your behalf. They change the environment they run in, and they decide what to do next. So, every team writes its own rules for what an agent may reach: a network rule here, a token there, a volume mount to get a task done. Those rules live in shell history, in dashboards, and in someone’s memory. A few months in, nobody can answer a simple question: what is this agent allowed to do? Every team answers that on its own today, and every runtime vendor could ship its own way of answering it. That’s the kind of fragmentation OCI was created to prevent. What we are announcing Kits are not new. Kits have been part of Docker Sandboxes as the way you package an agent, its tools, and what it may reach into something a team can share. What’s new is the artifact. A Kit is now an ordinary OCI image, and the format that describes it is open. Today at WeAreDevelopers, we announced the Docker Sandbox Kit Spec, open source under Apache 2.0. A Kit carries three things in one image: the agent, its tools, and a typed list of everything it asks to reach, such as hosts, credentials, and volumes. Because the list is part of the image, pinning the image pins the agent and its requests together. A Kit is not a new artifact type and not a fork of any OCI specification. It uses an extension point OCI already defines. It builds, pushes, pulls, signs, and scans like any image you run today, because it is one. Today, we’re bringing the spec to CNCF, under their neutral governance, just like we did when the image format went to OCI. Why it matters Adoption is free. Because a Kit is an OCI image, every registry, scanner, and signing tool you already run handles it. There is nothing new to deploy. The answer travels with the agent. Because the requests are in the image, “what may this agent do” has one answer. A teammate can pull it. A reviewer can diff it. A conforming runtime can enforce it. When a new version asks for more, the change shows up as added lines someone can refuse. An ecosystem, not a format Docker has always had an ecosystem-first mindset. The Dockerfile mattered because anyone could write one, any registry could store the result, and any runtime could run it. Kits follow the same approach, and we did not build them alone. We have worked with AWS, Box, Datadog, Dynatrace, JFrog, NanoClaw, OpenClaw, Palo Alto Networks, Snyk, and more to build Kits for their tools. Cloud platforms, observability, security, artifact management, content, and agent frameworks are all represented. The Kits we unveiled during the opening keynote at WeAreDevelopers today are the product of all that work, and they are the first of many. MCP gave agents a standard way to talk to a tool. Kits give the ecosystem a standard way to publish the whole arrangement: the agent, its tools, and what it asks to reach, in one image anyone can pull. That’s what turns a format into a supply chain. For example, a database vendor can publish a Kit that connects any agent to its service with the scope it recommends.An agent maker publishes its own Kit, so the request list comes from the people who built the agent. A platform team publishes one for the company, and every engineer starts from the same place. None of that happens if the format belongs to one vendor. A standard for deciding what an agent may do is worth a good deal less if it belongs to whoever sells you the runtime. Docker Sandboxes is the first runtime that enforces it. It should not be the only one, and under CNCF governance, it will not be. Containers made software portable. Kits make authority portable: the set of things you deliberately hand over to an agent travels with the agent, in the same image, and means the same thing wherever a conforming runtime opens it. “Standards are what let an ecosystem move fast without fragmenting, and few companies understand that better than Docker. By delivering Sandbox Kits as standard OCI images, Docker is giving the industry an open, repeatable way to package an AI agent, its tools, and its guardrails as one artifact. OCI is the foundation the cloud native ecosystem is built on, so a standard for agents that builds on OCI reaches the whole ecosystem at once. The CNCF welcomes this, and we’re excited to work with Docker and the community on making it broadly adopted.“ Chris Aniszczyk CTO at CNCF Build a Kit If you make a tool agents use, publish a Kit for it. If you run agents, start from one and share it with your team. The specification, the capability pages, and a worked tour of a real Kit are at docker/sandbox-kit-spec. If there is a Kit you cannot express, or a rule a runtime cannot implement, open an issue. Every Kit published and every issue filed is how a standard gets built. About the Authors Eli Aleyner Vice President, Product Strategy & Alliances, Docker Srini Sekaran Principal Product Marketing Manager for AI, Docker Srini Sekaran is Principal PMM for AI at Docker, focused on Docker AI Governance, Docker Sandboxes, and the future of agent infrastructure and developer workflows. CNCF Docker Open Container Initiative (OCI) Sandbox Kit sandboxes Company Partnerships Products Table of contents Related Posts Sep 24, 2026 Manufacturing Trust for AI Agents | Docker’s WeAreDevelopers Keynote Docker’s WeAreDevelopers keynote shows how Sandboxes, Kits, and Cloud Sandboxes give AI agents strong isolation and reproducible authority. Deanna Sparks Read now Oct 1, 2026 Trust Docker for the agents you don’t At WeAreDevelopers, Docker introduced Cloud Sandboxes, the open Sandbox Kit specification, and a commitment to bring Kits to the CNCF for neutral governance. Docker Team Read now Sep 24, 2026 From Dockerfile to Kit: the Docker Sandboxes Kit Specification Docker’s Sandbox Kit Specification v3 packages an AI agent’s network rules, credentials, and volumes as an ordinary, pinnable OCI image. Christian Dupuis Read now Products Products Overview Docker Desktop Docker Hub Docker Scout Docker Hardened Images Docker Sandboxes AI Governance MCP Enterprise Gateway Features Command Line Interface IDE Extensions Container Runtime Docker Extensions Trusted Open Source Content Secure Software Supply Chain Developers Documentation Getting Started Trainings Extensions SDK Community Open Source Preview Program Newsletter Pricing Personal Pro Team Business Premium Support and TAM Pricing FAQ Contact Sales Company About Us What is a Container Blog Why Docker Trust Customer Success Partners Events Docker System Status Newsroom Swag Store Brand Guidelines Trademark Guidelines Careers Contact Us Languages English 日本語 © 2026 Docker Inc. All rights reserved Terms of Use Privacy Legal Cookie Settings
