Docker Sandboxes
The sbx interface for local coding-agent isolation and Docker-managed cloud sandboxes.
Routing Summary
Use for Docker-oriented agent workflows. Compare Smol Machines for a portable VM engine/API and CubeSandbox for an operated sandbox fleet.
Verified documentation
Local and cloud backends have separate secrets, policies, and lifecycle controls. Moving copies filesystem state into a separate destination; it does not transfer memory or running processes, host mounts, or managed secrets. Configure destination network policy separately. Source: Docker local/cloud comparison, checked 2026-09-25 Source: official documentation, checked 2026-09-25
Evidence status
Documentation review only; no account setup, workload benchmark, or isolation test was performed. Keep rules, skills, approvals, source history, and proof in Kevin's control plane. Provider execution must remain replaceable. See Agent Sandboxes for the comparison contract.
Timeline
- 2026-09-25 | Recovered this provider identity from the July 7 test2 snapshot and rewrote it against current primary documentation. Source: test2 snapshot