- Sources: primary, discussion
- Summary: Docker's product page states each agent runs in a dedicated microVM with only the project workspace mounted, that the host is untouched, and that permissive execution is the default rather than an opt-in. It names Claude Code, Gemini CLI, Copilot CLI, Codex, OpenCode, and Kiro as supported out of the box, publishes install paths for a
sbx binary on macOS, Windows, and Ubuntu, and states Docker Desktop is not required. The page labels Sandboxes Experimental, supported through community channels, with functional and API limits and features that can change without notice, and holds network policy, filesystem rules, and org-wide MCP governance back to the paid Docker AI Governance product. The page carries no dated release announcement and this run found no matching launch post on Docker's blog, so what is recorded here is the page's own statement of scope and status rather than a ship date. - Why it matters: Isolation for running an agent with permission prompts off is offered as vendor infrastructure rather than a per-team script, while the controls a team would need to constrain it are held behind a paid tier.
- Follow-up: Whether Sandboxes leaves Experimental, and whether network and filesystem policy stay behind the paid tier.
send feedback on this story