An AI agent’s permissions just became something a team can pull, diff and sign.
- Docker published the Sandbox Kit Spec and brought it to the Cloud Native Computing Foundation, which will govern the format.
- A Kit is one OCI image. It carries the agent, its tools, and a typed list of everything it asks to reach, hosts, credentials and volumes.
- Because the list rides inside the image, pinning the image pins the agent and its requests together. A version that asks for more shows up as added lines a reviewer can refuse.
- Nothing new to deploy. Existing registries, scanners and signers already handle OCI images. AWS, Box, Datadog, Dynatrace, JFrog, OpenClaw, Palo Alto Networks and Snyk built Kits.
- The catch is enforcement. Docker Sandboxes is the first runtime that reads the list, and Docker says it should not be the only one.
Read the full analysis. Docker Put an Agent’s Permissions Inside the Image It Runs
Get the next one before it is old news
Independent analysis of cloud-native infrastructure, Kubernetes and data center economics. No vendor spin.
