Docker Sandboxes: a microVM with secrets manager and network policies to contain rogue agents
mdelapenya · x · 2026-09-08
Testcontainers maintainer mdelapenya breaks down Docker Sandboxes (sbx): not just another 'sandbox', but a microVM with a specialized container runtime, shipping a secrets manager plus network/filesystem policies to protect your host from agents doing nasty things.
- microVM architecture with a dedicated container runtime.
- Built-in secrets manager swaps credentials on the fly so agents never see real secrets.
- Network and filesystem policies allow/block domains on demand to control agent egress.
- Docs, conference talks, and a workshop are available.
Related event: Docker Sandboxes Meets OpenClaw: Sandbox Boundaries Debated(5 posts)→
More from coding & agent
- xbrlkit: open-source XBRL layer over Arelle with built-in MCP server support — jfrench009 · 2026-09-09
- Herdr lead agent orchestrates sub-agents with worktree and PR skills, dev ditches the GUI — iannuttall · 2026-09-09
- Session acting weird? Open a new one: practitioners' fix for momentum prior and context rot — gerardsans · 2026-09-09
- Dev Adds a Complete Tech Tree With GPT-6 Astra in 2h21m — Dimillian · 2026-09-09
- Cheap models via OpenRouter fall apart in agentic harnesses: GLM and DeepSeek can't match Claude — scottyLogJobs · 2026-09-09
- Multi-agent coding's hardest problem: deciding who is allowed to change what — apghere · 2026-09-09