Tech
Docker Has Launched Sandboxes, a New Product Providing Disposable, Isolated Microvm Environments for AI Coding Agents

The sandboxes protect a user's filesystem and network from agents running inside them, allowing agents to install packages, run services, and work unattended. Out of the box, Docker Sandboxes support Claude Code, Gemini CLI, Copilot CLI, Codex, OpenCode, and Kiro, with the option to create custom setups. The microVM-based isolation offers stronger security than standard VMs without the full performance cost, enabling agents to safely perform tasks requiring more permissions, such as running additional Docker containers.
For teams needing centralized enforcement of network policies, filesystem rules, and MCP governance across all developers, Docker recommends its AI Governance product. The feature is particularly relevant for 'YOLO mode' operations (--dangerously-skip-permissions), which grant agents full autonomy without approval prompts—a speed advantage that becomes risky without proper guardrails.
Source: Hacker News
Most read in this category
Loading article…