
Docker brings v3 Sandbox Kit specification to CNCF to package AI-agent permissions as OCI images
AI agents · Friday, 2 October 2026
Why it matters
For an agent-platform founder, this offers a concrete security and deployment pattern: treat permissions as signed, scannable, admission-controlled artifacts alongside the agent and its tools, with deny-by-default composition and update locking. The lack of a second conformant runtime means interoperability is still an open product and standards risk rather than a proven market capability.
What happened
Docker submitted its Apache 2.0 Sandbox Kit Specification, now at version 3, to the CNCF, defining AI-agent permissions as versioned declarations inside standard OCI images. Kits can specify network, credential, and volume access; explicit denials override grants, proxy-managed credentials can keep real tokens out of the sandbox, and pinning an image digest also pins its permissions. Docker says the design was tested with AWS, Snyk, Datadog, and other partners, but the specification has not been formally accepted into a CNCF program and Docker Sandboxes is currently its only conformant runtime, so cross-runtime portability remains un demonstrated.
Players & places
- Docker
- Cloud Native Computing Foundation
- AWS
- Snyk
- Datadog
- Palo Alto Networks