proomt

Search

Search posts, papers, and topics

All posts

InfoQSergio De Simone2 min readrelease notesintermediate

Docker Cloud Sandboxes Provide a Consistent Sandbox Abstraction Across Laptop and Cloud

Summary

Docker Cloud Sandboxes provide secure, hosted microVM execution environments for AI coding agents, extending local Docker Sandboxes to the cloud. This allows developers to seamlessly move long-running agent workloads between local machines and Docker-managed infrastructure using a unified CLI.

  • Cloud Sandboxes enable persistent, scalable execution of AI coding agents beyond local machines.
  • They offer hardware-enforced microVM isolation for consistent and secure environments.
  • Workloads can be moved between local and cloud with a single `sbx move` command, capturing the filesystem state.
  • Kits, pre-configured sandboxes, are now packaged as standard OCI images, integrating with Docker workflows.

Engineers building and running long-horizon AI coding agents can leverage this for scalable, persistent, and secure execution environments that bridge local development and cloud deployment.

6/10

Related reading

  1. Trust Docker for the agents you don’t

    Docker Cloud Sandboxes provide isolated microVM environments for running AI agents, enabling developers to start tasks locally and seamlessly move them to Docker-managed cloud compute. This offers enhanced security through containment and control, allowing agents to run longer tasks with explicit access policies.

    Dockerdocker.com9 min
  2. Manufacturing Trust for AI Agents | Docker’s WeAreDevelopers Keynote

    Docker announced a suite of tools—Docker Sandboxes, Sandbox Kits, and Cloud Sandboxes—to give AI agents isolated, reproducible environments with controllable access, and to let work move seamlessly from a developer’s laptop to the cloud. The approach uses microVM isolation, OCI‑based Kits, and an open spec submitted to CNCF, aiming to build a trusted, standards‑based agent ecosystem.

    Dockerdocker.com4 min
  3. For SeaVerse, GKE Agent Sandbox reduces infrastructure costs by 60%

    SeaVerse uses GKE Agent Sandbox (Kata Containers + Cloudhypervisor or gVisor) to run isolated AI sandboxes at scale, achieving 300 allocations / s per cluster (90% ≤ 200 ms) and cutting infrastructure spend by up to 60% via flexible VM sizing and per‑sandbox persistent storage, while gaining native Cloud observability.

    Google Cloud Bloggoogle.com5 min
  4. The case for a cloud native agent harness

    This article proposes a "cloud-native agent harness" architecture, exemplified by the open-source Mecatl, which decouples the agent loop from its environment. This enables running AI agents as distributed applications, offering durability, governed tool access, and multi-client support beyond a single desktop.

    CNCFcncf.io5 min