< Back to all clusters
[TECHNOLOGY] · 2 sources

started · updated

Docker launches Cloud Sandboxes to secure AI agents

Docker has launched Cloud Sandboxes, a new service designed to provide enhanced security and isolation for AI agents. The service extends Docker’s local sandboxing technology to cloud infrastructure using a microVM (micro virtual machine) architecture. Unlike traditional containers that share a host kernel, these sandboxes run in dedicated microVMs with independent kernels and hardware-level isolation, such as Intel VT-x or AMD-V, to prevent agents from accessing sensitive host data.

Docker President and COO Mark Cavage noted that while containers are effective for many uses, they were not specifically designed for the isolation levels required by AI agents, which often attempt to probe or mutate their environments. The Cloud Sandboxes feature sub-second boot times, per-second billing, and built-in security measures including network egress firewalls and credential injection via network proxies.

Additionally, Docker introduced the Kits specification (v3), an open standard for packaging AI agent sandboxes as OCI-compliant images. This specification defines rules for network permissions, disk mounting, and port mapping. Docker has committed to submitting the Kits specification to the Cloud Native Computing Foundation (CNCF) for neutral governance under an Apache 2.0 license.

Entities

Anthropic · Cloud Native Computing Foundation · Docker · Mark Cavage · OpenAI