基础设施 4.0 · 优秀 2026-08-10 · 文章

Docker Sandboxes: Sandboxes for Coding Agents

Docker 给 coding agent 提供独立 microVM,只挂载项目工作区,允许 agent 在隔离环境里安装依赖修改配置和再启动容器Sandbox 默认可销毁,支持 Claude CodeCopilot CLICodexKiro 和 OpenCode,覆盖 macOSWindowsUbuntu性能描述如比虚拟机更快没有测试数据,适合先在非敏感仓库验证启动成本和隔离效果

打开原文回到归档

Docker Sandboxes: Sandboxes for Coding Agents

Source: <https://www.docker.com/products/docker-sandboxes/&gt;
Author: Docker
Original date: 2026-08-10
Captured: 2026-08-11 (AAIF daily-intake-evening)

中文摘要

Docker 给 coding agent 提供独立 microVM,只挂载项目工作区,允许 agent 在隔离环境里安装依赖、修改配置和再启动容器。Sandbox 默认可销毁,支持 Claude Code、Copilot CLI、Codex、Kiro 和 OpenCode,覆盖 macOS、Windows、Ubuntu。性能描述如“比虚拟机更快”没有测试数据,适合先在非敏感仓库验证启动成本和隔离效果。

English Summary

Docker Sandboxes give coding agents their own microVM with only the project workspace mounted; agents can install dependencies, rewrite config, and restart containers in isolation. Sandboxes are disposable by default, support Claude Code, Copilot CLI, Codex, Kiro and OpenCode, and ship for macOS, Windows, Ubuntu. Performance claims like 'faster than a VM' lack benchmarks; validate cold-start cost and isolation on non-sensitive repos.

一句话

agent 隔离从权限判断挪到运行环境,代价是启动 microVM

Source Body Excerpt

Docker Sandboxes | Sandboxes for Coding Agents

作者: @Docker
原文链接: https://www.docker.com/products/docker-sandboxes/

Docker Sandboxes

Run AI agents safely in local sandboxes.

Disposable, isolated sandboxes for AI agents like Claude Code, Copilot CLI, Codex, OpenCode, and Kiro that need safe, unattended execution.

macOS

$ brew trust docker/tap && brew install docker/tap/sbx

Copy

Windows

\> winget install Docker.sbx

Copy

Linux (Ubuntu)

$ curl -fsSL https://get.docker.com | sudo REPO\_ONLY=1 sh

$ sudo apt-get install docker-sbx

Copy

[

Get started free](#get-started)[

Watch demo](#demo)

See it in action

Sandboxes in action.

Watch an agent install packages, run Docker, modify configs, and execute unattended. Then dispose of the sandbox in one command.

sbx-demo ▶ Run Demo

Click "Run Demo" to start

Get started

Get started in seconds.

macOS

$ brew trust docker/tap && brew install docker/tap/sbx

Copy

Windows

\> winget install Docker.sbx

Copy

Linux (Ubuntu)

$ curl -fsSL https://get.docker.com | sudo REPO\_ONLY=1 sh

$ sudo apt-get install docker-sbx

Copy

Read the docs

Why sandboxes

Give agents the autonomy they need to get work done, safely.

Agents do their best work when they have freedom. Sandboxes let them run fast without running wild, so speed and safety stop being a tradeoff.

[

Filesystem

](#filesystem)[

Network

](#network)[

Credentials

](#credentials)

Need to enforce these controls across your whole team?

That’s Docker AI Governance

Capabilities

YOLO mode, safely.

Each agent runs inside a dedicated microVM with your dev environment and only your project workspace mounted in. Agents can install packages, modify configs, and spin up their own Docker containers. Your host stays untouched. No manual review, no permission prompts, no supervision required.

Customizable Safe Execution

Network and filesystem controls you define.

Enforceable org-wide with Docker AI Governance.

MicroVM Isolation

Hard security boundary from the host.

Fast to Spin Up, Easy to Tear Down

Disposable by default. Faster than VMs.

Agents Can Use Docker Too

Agents can spin up containers within Sandboxes.

Real Dev Environment

Install packages, run services, work unattended.

One Sandbox for All Your Coding Agents

Claude Code, Copilot CLI, Codex, Kiro, OpenCode.

Default –dangerously-skip-permissions Use permissive modes with confidence. In fact, that’s the default.

Works with leading coding agents

Every team is about to have their own team of AI agents doing real work for them. The question is whether it can happen safely. NanoClaw was built on the principle that you don’t trust agents with security, you build walls around them. Docker has been ahead of the curve on exactly this. Docker Sandboxes is what that looks like at the infrastructure level, making it possible for organizations to get the full value from agents without compromising on security.

Gavriel Cohen

Creator of NanoClaw, NanoClaw

Docker Sandboxes let agents have the autonomy to do long-running tasks without compromising safety. We’re excited to integrate Sandboxes into Warp so that developers can run agents freely with a consistent environment, regardless of whether agents are running locally or in the cloud.

Ben Navetta

Engineering Lead, Warp

Give agents freedom. Keep what matters safe.

macOS

$ brew trust docker/tap && brew install docker/tap/sbx

Copy

Windows

\> winget install Docker.sbx

Copy

Linux (Ubuntu)

$ curl -fsSL https://get.docker.com | sudo REPO\_ONLY=1 sh

$ sudo apt-get install docker-sbx

Copy

Read the docs to get started

FAQ

Common questions.

What is a sandbox for AI coding agents?

A sandbox is a microVM isolated environment that protects your filesystem and network from agents running inside it.

Which coding agents are supported?

Out of the box we support Claude Code, Gemini CLI, Copilot CLI, Codex, OpenCode, Kiro. You can also create your own

What does “YOLO mode” mean, and is it safe?

YOLO mode (--dangerously-skip-permissions) gives agents autonomy with no approval prompts. Essential for speed, but risky without guardrails. Sandboxes make it safe by isolating each agent inside a dedicated microVM.

How is a sandbox different from a VM?

Sandboxes run fully isolated in microVMs, giving more isolation without paying the full cost of running a VM. This lets them do things that need more permissions safely, like running additional Docker containers.

What safety controls can I configure?

To define these once and enforce them on every developer’s machine, see Docker AI Governance.

Do I need Docker Desktop to use sandboxes?

No.

What if I need additional admin controls?

Installing Sandboxes covers core functionality. For centralized controls across a team such as network policies, filesystem rules, MCP governance: Docker AI Governance.

Need More Control Over Your Sandboxes?

With Docker Sandboxes, your developers get isolated environments to run agents freely and safely. When your team needs to go further with network access restrictions, filesystem policies, and centralized admin controls, we can help you configure the right setup. Docker AI Governance adds network access policies, filesystem controls, and org-wide MCP governance: defined once, enforced everywhere. Talk to us about:

  • Network access policies for sandbox environments
  • Filesystem access controls and restrictions
  • Admin-level configuration for your team

Talk to an expert

Thank you for your interest. The Docker Team will be in touch