<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/docker-brings-sandbox-kit-spec-to-the-cncf-s5knbsucl" -->

---
title: Docker Brings Sandbox Kit Spec to the CNCF | daily.dev
description: Docker is donating its new Sandbox Kit Spec to the CNCF, an open source (Apache 2.0) standard for packaging AI agents, their tools, and a typed list of...
canonical: https://daily.dev/posts/docker-brings-sandbox-kit-spec-to-the-cncf-s5knbsucl
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Docker Brings Sandbox Kit Spec to the CNCF | daily.dev
og:description: Docker is donating its new Sandbox Kit Spec to the CNCF, an open source (Apache 2.0) standard for packaging AI agents, their tools, and a typed list of...
og:url: https://daily.dev/posts/docker-brings-sandbox-kit-spec-to-the-cncf-s5knbsucl
og:image: https://api.daily.dev/og/posts/s5KnbsUCL.png
og:image:alt: Docker Brings Sandbox Kit Spec to the CNCF
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Docker Brings Sandbox Kit Spec to the CNCF

**[Docker](https://daily.dev/sources/docker)** · 6 min read · 1 upvotes · 0 comments

## Summary

Docker is donating its new Sandbox Kit Spec to the CNCF, an open source (Apache 2.0) standard for packaging AI agents, their tools, and a typed list of everything they may access (hosts, credentials, volumes) into a single OCI image called a Kit. Because a Kit is an ordinary OCI image, it works with existing registries, scanners, and signing tools without new infrastructure. Docker Sandboxes is the first runtime to enforce the spec, but CNCF governance is meant to keep it vendor-neutral, similar to how Docker donated its image format and Runc runtime to form the OCI a decade ago. Partners including AWS, Box, Datadog, Dynatrace, JFrog, and Snyk have already built Kits for their tools, announced at WeAreDevelopers.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://www.docker.com/blog/docker-sandbox-kit-spec-cncf>

## Questions this post answers

### What is the Docker Sandbox Kit Spec and what does it do?

It is an open source specification, released under Apache 2.0, that packages an AI agent, its tools, and a typed list of everything the agent may access, such as hosts, credentials, and volumes, into a single OCI image called a Kit. Because the access list is embedded in the image, pinning the image pins the agent and its permitted requests together, and it works with existing container registries, scanners, and signing tools.

_Anyone standardizing AI agent permissions can follow Sandbox Kit developments on daily.dev._

### Why did Docker bring the Sandbox Kit Spec to the CNCF instead of keeping it proprietary?

Docker wants the format governed neutrally so no single runtime vendor controls what an AI agent is allowed to do, mirroring how Docker donated its image format and Runc runtime to form the Open Container Initiative a decade earlier. Docker Sandboxes is currently the first runtime enforcing the spec, but CNCF governance is meant to ensure other runtimes can adopt it too.

_Teams weighing vendor lock-in for agent tooling can track how this governance shift plays out on daily.dev._

### Which companies have already built Kits using the Docker Sandbox Kit Spec?

AWS, Box, Datadog, Dynatrace, JFrog, NanoClaw, OpenClaw, Palo Alto Networks, and Snyk collaborated with Docker to build Kits covering cloud platforms, observability, security, artifact management, content, and agent frameworks, unveiled during the WeAreDevelopers opening keynote.

_Developers evaluating agent tooling ecosystems can follow these Kit integrations on daily.dev._

## Similar posts on daily.dev

- [Why Empty Sandboxes Break Developer Experience](https://daily.dev/posts/why-empty-sandboxes-break-developer-experience-yj5w3qscv) · Docker · 1 upvotes · 0 comments
- [The Questions Every Team Asks About Docker Sandboxes](https://daily.dev/posts/the-questions-every-team-asks-about-docker-sandboxes-dea3ny4vm) · Cloud Native Now · 0 upvotes · 0 comments
- [Open-Source Agent Sandbox Enables Secure Deployment of AI Agents on Kubernetes](https://daily.dev/posts/open-source-agent-sandbox-enables-secure-deployment-of-ai-agents-on-kubernetes-ichq19lcg) · InfoQ · 1 upvotes · 0 comments
- [Agent Sandboxing: Comparing OpenSandbox vs. Docker](https://daily.dev/posts/agent-sandboxing-comparing-opensandbox-vs-docker-s1qwhk5xm) · SitePoint · 1 upvotes · 0 comments

---

Tags: [#ai-agents](https://daily.dev/tags/ai-agents), [#docker](https://daily.dev/tags/docker), [#cncf](https://daily.dev/tags/cncf)

[View this post on daily.dev](https://daily.dev/posts/docker-brings-sandbox-kit-spec-to-the-cncf-s5knbsucl)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"Docker Brings Sandbox Kit Spec to the CNCF","url":"https://daily.dev/posts/docker-brings-sandbox-kit-spec-to-the-cncf-s5knbsucl","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/docker-brings-sandbox-kit-spec-to-the-cncf-s5knbsucl"},"datePublished":"2026-09-24T16:03:29.210Z","dateModified":"2026-09-24T16:03:54.657Z","description":"Docker is donating its new Sandbox Kit Spec to the CNCF, an open source (Apache 2.0) standard for packaging AI agents, their tools, and a typed list of...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/7be8a0db8ab91f7126d8d6f3da0e7f7f?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/7be8a0db8ab91f7126d8d6f3da0e7f7f?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"Docker","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"Docker","logo":"https://media.daily.dev/image/upload/t_logo,f_auto/v1/logos/8a1022bebfc04a7d824c309bd3686787","url":"https://daily.dev/sources/docker"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/docker-brings-sandbox-kit-spec-to-the-cncf-s5knbsucl","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":1},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"ai-agents,docker,cncf","timeRequired":"PT6M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"Docker","item":"https://daily.dev/sources/docker"},{"@type":"ListItem","position":3,"name":"Docker Brings Sandbox Kit Spec to the CNCF"}]}
{"@context":"https://schema.org","@type":"FAQPage","@id":"https://daily.dev/posts/docker-brings-sandbox-kit-spec-to-the-cncf-s5knbsucl#faq","mainEntity":[{"@type":"Question","name":"What is the Docker Sandbox Kit Spec and what does it do?","acceptedAnswer":{"@type":"Answer","text":"It is an open source specification, released under Apache 2.0, that packages an AI agent, its tools, and a typed list of everything the agent may access, such as hosts, credentials, and volumes, into a single OCI image called a Kit. Because the access list is embedded in the image, pinning the image pins the agent and its permitted requests together, and it works with existing container registries, scanners, and signing tools. Anyone standardizing AI agent permissions can follow Sandbox Kit developments on daily.dev."}},{"@type":"Question","name":"Why did Docker bring the Sandbox Kit Spec to the CNCF instead of keeping it proprietary?","acceptedAnswer":{"@type":"Answer","text":"Docker wants the format governed neutrally so no single runtime vendor controls what an AI agent is allowed to do, mirroring how Docker donated its image format and Runc runtime to form the Open Container Initiative a decade earlier. Docker Sandboxes is currently the first runtime enforcing the spec, but CNCF governance is meant to ensure other runtimes can adopt it too. Teams weighing vendor lock-in for agent tooling can track how this governance shift plays out on daily.dev."}},{"@type":"Question","name":"Which companies have already built Kits using the Docker Sandbox Kit Spec?","acceptedAnswer":{"@type":"Answer","text":"AWS, Box, Datadog, Dynatrace, JFrog, NanoClaw, OpenClaw, Palo Alto Networks, and Snyk collaborated with Docker to build Kits covering cloud platforms, observability, security, artifact management, content, and agent frameworks, unveiled during the WeAreDevelopers opening keynote. Developers evaluating agent tooling ecosystems can follow these Kit integrations on daily.dev."}}]}
```

