cd /news/ai-tools/docker-sandboxes-disposable-isolated… · home topics ai-tools article
[ARTICLE · art-89960] src=docker.com ↗ pub= topic=ai-tools verified=true sentiment=↑ positive

Docker Sandboxes – Disposable, isolated sandboxes for AI agents

Docker Inc. has launched Docker Sandboxes, a new product that provides disposable, isolated microVM environments for AI coding agents such as Claude Code, Gemini CLI, Copilot CLI, Codex, OpenCode, and Kiro, enabling safe unattended execution. The sandboxes offer customizable network and filesystem controls, hard security boundaries from the host, and support for agents to spin up containers within them. Docker Sandboxes can be installed via Homebrew with 'brew trust docker/tap && brew install docker/tap/sbx' and are available for individual developers, with Docker AI Governance offering centralized controls for teams.

read2 min views1 publishedAug 10, 2026
Docker Sandboxes – Disposable, isolated sandboxes for AI agents
Image: source

Claude Code, Gemini CLI, Copilot CLI, Codex, OpenCode, and

Kiro that need safe, unattended execution.

Sandboxes in action. #

Get started in seconds. #

brew trust docker/tap && brew install docker/tap/sbx

Give agents the autonomy they need to get work done, safely. #

Need to enforce these controls across your whole team?

That’s Docker AI Governance

YOLO mode, safely. #

Customizable Safe Execution

Network and filesystem controls you define.

MicroVM Isolation

Hard security boundary from the host.

Fast to Spin Up, Easy to Tear Down

Disposable by default. Faster than VMs.

Agents Can Use Docker Too

Agents can spin up containers within Sandboxes.

Real Dev Environment

Install packages, run services, work unattended.

One Sandbox for All Your Coding Agents

Claude Code, Gemini CLI, Copilot CLI, Codex, Kiro, OpenCode.

Works with leading coding agents #

Common questions. #

What is a sandbox for AI coding agents?

A sandbox is a microVM isolated environment that protects your filesystem and network from agents running inside it.

Which coding agents are supported?

Out of the box we support Claude Code, Gemini CLI, Copilot CLI, Codex, OpenCode, Kiro. You can also create your own

What does “YOLO mode” mean, and is it safe?

YOLO mode (--dangerously-skip-permissions ) gives agents autonomy with no approval prompts. Essential for speed, but risky without guardrails. Sandboxes make it safe by isolating each agent inside a dedicated microVM.

How is a sandbox different from a VM?

Sandboxes run fully isolated in microVMs, giving more isolation without paying the full cost of running a VM. This lets them do things that need more permissions safely, like running additional Docker containers.

What safety controls can I configure?

To define these once and enforce them on every developer’s machine, see Docker AI Governance.

Do I need Docker Desktop to use sandboxes?

No.

What if I need additional admin controls?

Installing Sandboxes covers core functionality. For centralized controls across a team such as network policies, filesystem rules, MCP governance: Docker AI Governance.

Need More Control Over Your Sandboxes?

Docker AI Governanceadds network access policies, filesystem controls, and org-wide MCP governance: defined once, enforced everywhere.

Talk to us about:

  • Network access policies for sandbox environments
  • Filesystem access controls and restrictions
  • Admin-level configuration for your team
── more in #ai-tools 4 stories · sorted by recency
── more on @docker inc. 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/docker-sandboxes-dis…] indexed:0 read:2min 2026-08-10 ·