proomt

Search

Search posts, papers, and topics

All posts

DockerPeiFang Sung4 min readintermediate

Manufacturing Trust for AI Agents | Docker’s WeAreDevelopers Keynote

Summary

Docker announced a suite of tools—Docker Sandboxes, Sandbox Kits, and Cloud Sandboxes—to give AI agents isolated, reproducible environments with controllable access, and to let work move seamlessly from a developer’s laptop to the cloud. The approach uses microVM isolation, OCI‑based Kits, and an open spec submitted to CNCF, aiming to build a trusted, standards‑based agent ecosystem.

  • Docker Sandboxes run each AI agent in an isolated microVM with configurable file, network, and secret policies.
  • Sandbox Kits package the agent, its tools, and its access policies as versioned OCI images, making authority reproducible and shareable.
  • Cloud Sandboxes let you start a sandbox locally and move it to Docker-managed cloud compute with a single command, preserving isolation.
  • Docker is submitting the Kits specification to the CNCF for neutral governance, aiming for an open standard across the ecosystem.

Engineers building AI agents need secure, reproducible execution environments that can scale from laptop to cloud while maintaining strict access controls.

5/10

Related reading

  1. Trust Docker for the agents you don’t

    Docker Cloud Sandboxes provide isolated microVM environments for running AI agents, enabling developers to start tasks locally and seamlessly move them to Docker-managed cloud compute. This offers enhanced security through containment and control, allowing agents to run longer tasks with explicit access policies.

    Dockerdocker.com9 min
  2. For SeaVerse, GKE Agent Sandbox reduces infrastructure costs by 60%

    SeaVerse uses GKE Agent Sandbox (Kata Containers + Cloudhypervisor or gVisor) to run isolated AI sandboxes at scale, achieving 300 allocations / s per cluster (90% ≤ 200 ms) and cutting infrastructure spend by up to 60% via flexible VM sizing and per‑sandbox persistent storage, while gaining native Cloud observability.

    Google Cloud Bloggoogle.com5 min
  3. Blog: How to Build a DevOps Agent

    This blog walks through the open‑source DevOps Agent Kit, which lets Claude Code or Cursor act as a DevOps assistant by connecting to CloudBees Unify, Jira, and Slack via MCP servers and to GitHub via the CLI. It provides a repeatable setup (Docker, Node, env file) and seven slash commands for pipeline overview, triage, security, release readiness, flag management, CI health scoring, and Jira tic…

    Codeshipcloudbees.com10 min
  4. Agent Substrate brings high-density, scalable, trusted infrastructure to GKE

    Agent Substrate is an open‑source runtime for AI agents that runs on GKE. It uses Cloud Hypervisor microVMs or gVisor sandboxes to give kernel‑level isolation, a custom control‑ and data‑plane that can suspend/resume agents in <500 ms, and a “zero‑idle” model that packs >1 000 dormant agents per host (≈10× density vs. containers). GKE integration adds custom ComputeClasses, spot/on‑demand pools,…

    Google Cloud Bloggoogle.com6 min