Introduction
Docker Sandboxes launched on August 10, 2026, giving AI coding agents a disposable microVM home on your own machine. Claude Code, Codex, Gemini CLI, Copilot CLI, OpenCode, and Kiro each run inside a dedicated sandbox, with only your project workspace mounted in. The host stays untouched, which makes Docker Sandboxes the practical way to run agents in permissive YOLO mode without the usual fear.
Why AI Coding Agents Need Sandboxes
Coding agents do their best work when they can install packages, modify configs, run services, and fire off commands without asking permission after every step. Most agents ship a skip-permissions flag for exactly this reason. In Claude Code that flag is called dangerously-skip-permissions, and it gets the job done fast. It also means a prompt injection, a bad tool call, or a misbehaving plugin can touch everything your user account can reach.
The common workarounds are devcontainers, hand-rolled scripts, or full virtual machines. Each one has friction. Devcontainers share the host kernel. Scripts like bubblewrap need per-machine setup. Full VMs are heavy and slow to boot. Docker's answer is a microVM per agent: real hardware virtualization, milliseconds to start, and nothing shared with your OS.
What Docker Sandboxes Are
A sandbox is a dedicated microVM per agent session. Docker installs a CLI called sbx, and that CLI handles provisioning, mounting, and teardown. Agents get a real development environment, can install packages, run services, and even spin up their own Docker containers inside the sandbox. Tear everything down with one command when the task is done.
The isolation matters more than the convenience. Filesystem and network controls are configurable, so an agent can be blocked from your home directory or from arbitrary internet access while still reaching a package registry. For teams, the same policies can be enforced org-wide through Docker AI Governance, which adds network access policies, filesystem rules, and MCP governance defined once and applied to every developer machine.
Technical Breakdown: MicroVM, Not Container
The key design choice is the microVM. A microVM is a real virtual machine with most of the hardware emulation stripped out, so it boots in milliseconds instead of seconds. That is what separates Sandboxes from devcontainers, where a kernel exploit or a naive mount can hit the host. A microVM gives a hard security boundary while staying cheap enough to create per task.
Inside the sandbox, agents run in what Docker calls YOLO mode. The docs describe it as default-dangerously-skip-permissions: no approval prompts, no manual review, no supervision. That is exactly the autonomy agents want, and the reason Docker can offer it as a default is the microVM behind it.
Agents can also use Docker within the sandbox. That matters for modern AI workflows, where an agent builds, tests, and deploys containers as part of one long task. The tooling also handles agent updates: sandbox images ship with the agent preinstalled, and when a new agent release exists, the VM notifies you on first run and updates after you approve.
Installation and Agent Support
Installation is a one-liner on both supported platforms:
You do not need Docker Desktop. Six coding agents work out of the box: Claude Code, Gemini CLI, Copilot CLI, Codex, OpenCode, and Kiro, and you can add your own. Documentation lives at docs.docker.com/ai/sandboxes. Docker also points to NanoClaw and Warp as early integrations, both pilots for the product during its preview.
How Developers Are Reacting
The launch hit the Hacker News front page the same day with around 270 points. Reactions split along predictable lines. People who already run devcontainers or bubblewrap wrappers for their agents asked what was new, which is fair: the isolation pattern is not novel, Docker's distribution and polish are. Others objected to signing in with a Docker account to use a local tool, and a few noted Linux instructions exist in the docs but are missing from the landing page. The most common takeaway in the thread was that Docker putting its weight behind agent sandboxing could push the whole ecosystem toward safer defaults.
Comparison Table: Sandboxing Approaches
| Approach | Isolation | Agents can run Docker inside | Setup effort |
|---|---|---|---|
| Docker Sandboxes | MicroVM, hard boundary | Yes | One command |
| Devcontainer | Container, shared kernel | Via workarounds | Config file |
| Bubblewrap script | Namespace isolation | No | Custom script |
| Full VM | Full virtualization | Yes | Manual install |
Frequently Asked Questions
What is a sandbox for AI coding agents?
A microVM that protects your filesystem and network from the agent running inside it. The agent works in an isolated environment with your project mounted, then the sandbox is disposed of.
Which coding agents are supported?
Claude Code, Gemini CLI, Copilot CLI, Codex, OpenCode, and Kiro out of the box. Custom agents can be added.
What does YOLO mode mean, and is it safe?
YOLO mode disables permission prompts: the agent acts with full autonomy. Sandboxes make it safe by confining the agent to a dedicated microVM, so the host is never at risk.
How is a sandbox different from a VM?
Sandboxes run in microVMs, which are smaller and start much faster than full VMs, while isolating the process just as strictly.
Do I need Docker Desktop to use Sandboxes?
No. The sbx CLI is standalone.
Can my team enforce sandbox policies centrally?
Yes, through Docker AI Governance, which covers network access, filesystem controls, and MCP governance across every developer machine.
Key Takeaways
- Docker Sandboxes wrap AI coding agents in disposable microVMs with a hard isolation boundary.
- Agents keep full autonomy, including running Docker inside the sandbox, while the host stays untouched.
- Setup is a single command on macOS and Windows, and Docker Desktop is not required.
- Filesystem and network policies can be enforced team-wide with Docker AI Governance.
Conclusion
Docker Sandboxes makes agent autonomy a safe default instead of a risky one. The microVM approach is not new, but shipping it as a one-command local tool with first-party agent support is. If your team runs Claude Code or Codex with skip-permissions, this is worth a look, and the pricing model keeps the core experience free to start.
Sources
Automated Transmission
This entry was synthesized and populated dynamically using native API integrations.