Shut the Laptop, Keep the Agent: Docker's Cloud Sandboxes and OCI Kits Redefine AI Agent Isolation
Docker extends its microVM agent isolation to the cloud — long-running agents survive a closed laptop, scale to 16 vCPUs, and ship as standard OCI images under a spec headed to the CNCF.
The pitch is almost comically simple: your AI agent has a six-hour refactor to grind through, and you would like to close your laptop and go to dinner. With Docker’s newly launched Cloud Sandboxes, announced September 24 at WeAreDevelopers North America, that is now the advertised workflow. Agents run in Docker-managed cloud infrastructure in the same microVM isolation they get locally, keep working unattended overnight, and hand back results when the developer returns. The company’s framing is blunt — the same sandbox, the same policies, whether the workload runs on a laptop or in Docker’s cloud.
What actually shipped
Docker Cloud Sandboxes extend the local sandbox product the company introduced earlier in 2026 into elastic cloud capacity. The technical claims are concrete: sandboxes boot in the “low hundreds of milliseconds” with secrets, policy, MCP gateways, and agent configuration already baked in; compute scales from 1 to 16 vCPUs with zero infrastructure provisioning; and workflows can start on a laptop and shift to the cloud mid-task without switching environments. Pricing is metered per second, starting at $0.07/hour for a 1-vCPU, 2 GB “Micro” shape and rising to $1.12/hour for 16 vCPUs and 32 GB, with model inference billed on the developer’s own API keys.
The second announcement may matter more than the first. Docker also published the next generation of Kits, its open specification for packaging an agentic sandbox — the agent, its tools, and the rules for what it may touch — as a single shareable artifact. Kits are now built as standard OCI images, the same format behind every container on Docker Hub, which means no proprietary packaging and no vendor lock-in. Access rules travel inside the Kit itself: define once what an agent can touch, and the policy is enforced everywhere the Kit runs. Kits also compose from “mixins,” letting enterprises standardize hardened components while teams customize the rest. Docker has committed to submitting the Kits specification to the Cloud Native Computing Foundation.
Why isolation, and why now
Docker’s argument is that containers were never designed for what AI agents demand. “While the containers Docker is known for still have a critical role to play, they weren’t designed for the level of isolation AI agents demand,” said Mark Cavage, President at Docker. A container shares the host kernel and, in the classic setup, hands the agent a mounted Docker socket that is functionally root. Agents that download and execute untrusted code, move files, and chase down build failures need a harder boundary — hence microVMs, per-sandbox network firewalls, credential injection through a proxy rather than ambient environment variables, and deterministic policies the agent cannot rewrite mid-task.
Chief Product Officer Mat Velloso tied the launch to a gap the industry keeps rediscovering: “Nobody needs convincing anymore that AI can drive real productivity gains. The problem that’s still largely unsolved is how to achieve those gains safely and with the right guardrails. Every organization that can’t unleash agents at scale without something breaking is leaving real value on the table.” Docker’s answer is isolation plus policy — a model- and harness-neutral environment that treats the agent as untrusted code execution, because that is what it is.
The competitive context
Docker is not alone in this market. Cloudflare, Vercel, Modal, E2B, Google, and others all sell or operate agent sandboxes, with published rates around $0.09–0.13 per vCPU-hour — Docker’s $0.07 entry price undercuts most of the field, though metering details and free-tier semantics differ. What Docker brings that the pure-play sandbox startups lack is distribution: millions of developers already run its CLI and publish to Docker Hub, and the local-to-cloud continuity means a team can evaluate isolation on a laptop before committing to cloud spend. The CNCF submission is the other differentiator. Chris Aniszczyk, CTO at CNCF, endorsed the OCI-based approach: “By delivering Sandbox Kits as standard OCI images, Docker is giving the industry an open, repeatable way to package an AI agent, its tools, and its guardrails as one artifact… a standard for agents that builds on OCI reaches the whole ecosystem at once.”
The Register’s coverage adds a useful reality check, noting that Docker is pitching “a simple, flexible set of compute shapes with simple low, low pricing” into a market where containment failures are still routine and where the definition of what a sandbox must block keeps expanding as agents grow more autonomous.
Analysis: the operating layer for agentic work
Strip away the launch language and the strategic bet is legible: Docker is trying to become the operating layer for agentic software the way it became the operating layer for cloud-native software a decade ago. The playbook is identical — take a painful, fragmented problem (then: “works on my machine”; now: “my agent escaped and deleted the wrong directory”), solve it with an open standard (then: OCI containers; now: OCI Kits), and monetize the managed cloud version of the standard. The local-first, cloud-second path also mirrors how Docker Desktop converted free users into paid ones.
Two open questions are worth tracking. First, whether the CNCF community actually adopts the Kits spec or fragments into competing agent-packaging formats — the sandbox market is crowded, and rivals have little incentive to standardize on a Docker-originated spec unless customers demand it. Second, whether policy-as-artifact genuinely solves enterprise trust. The hardest part of agent governance was never the packaging; it is deciding what the agent may touch, keeping that decision current as the task mutates, and auditing what happened after the fact. Kits move the enforcement problem forward, but the definition and audit problems remain open — which is presumably why Docker pairs the launch with its separate AI Governance product.
For developers, the immediate value is real regardless of the standards outcome: overnight agent runs, per-second billing, and isolation boundaries that survive a laptop lid closing. The era of babysitting an agent from a terminal window is ending, one microVM at a time.
Sources
- [1] https://www.docker.com/press-release/cloud-sandboxes-extending-secure-ai-agent-isolation-beyond-the-laptop/
- [2] https://www.theregister.com/ai-and-ml/2026/09/24/dockers-new-sandboxes-aim-to-contain-ai-agents-for-real/
- [3] https://www.helpnetsecurity.com/2026/09/25/docker-launches-cloud-sandboxes/
- [4] https://www.docker.com/products/docker-sandboxes/
- [5] https://www.techzine.eu/news/devops/144555/docker-brings-sandboxes-for-ai-agents-to-the-cloud/