proomt

Search

Search posts, papers, and topics

All posts

DockerJin Kim9 min readintermediate

Trust Docker for the agents you don’t

Summary

Docker Cloud Sandboxes provide isolated microVM environments for running AI agents, enabling developers to start tasks locally and seamlessly move them to Docker-managed cloud compute. This offers enhanced security through containment and control, allowing agents to run longer tasks with explicit access policies.

  • Cloud Sandboxes run agents in isolated microVMs with their own kernel and Docker daemon for security.
  • The workflow supports starting agent tasks locally and migrating them to cloud compute, then bringing results back.
  • The open Sandbox Kit specification (an OCI image) defines agent environments and their requested access, enabling shared, reviewable configurations.
  • Runtime governance enforces policies (e.g., network access, credential usage) outside the agent, enhancing control.

Engineers building and deploying AI agents should care about this for secure, scalable, and auditable execution environments that mitigate risks associated with autonomous agent actions.

6/10

Related reading

  1. Manufacturing Trust for AI Agents | Docker’s WeAreDevelopers Keynote

    Docker announced a suite of tools—Docker Sandboxes, Sandbox Kits, and Cloud Sandboxes—to give AI agents isolated, reproducible environments with controllable access, and to let work move seamlessly from a developer’s laptop to the cloud. The approach uses microVM isolation, OCI‑based Kits, and an open spec submitted to CNCF, aiming to build a trusted, standards‑based agent ecosystem.

    Dockerdocker.com4 min
  2. For SeaVerse, GKE Agent Sandbox reduces infrastructure costs by 60%

    SeaVerse uses GKE Agent Sandbox (Kata Containers + Cloudhypervisor or gVisor) to run isolated AI sandboxes at scale, achieving 300 allocations / s per cluster (90% ≤ 200 ms) and cutting infrastructure spend by up to 60% via flexible VM sizing and per‑sandbox persistent storage, while gaining native Cloud observability.

    Google Cloud Bloggoogle.com5 min
  3. Vercel Sandbox now supports Devin Outposts

    Vercel Sandbox adds support for Devin Outposts, letting each AI agent session run in an isolated microVM with snapshot state and firewall controls. Teams can deploy via a provided quickstart and get automatic credential handling.

    Vercelvercel.com1 minrelease
  4. Agent Substrate brings high-density, scalable, trusted infrastructure to GKE

    Agent Substrate is an open‑source runtime for AI agents that runs on GKE. It uses Cloud Hypervisor microVMs or gVisor sandboxes to give kernel‑level isolation, a custom control‑ and data‑plane that can suspend/resume agents in <500 ms, and a “zero‑idle” model that packs >1 000 dormant agents per host (≈10× density vs. containers). GKE integration adds custom ComputeClasses, spot/on‑demand pools,…

    Google Cloud Bloggoogle.com6 min