4 ms·
I work at Docker. Lot of valid and useful feedback here that we're looking closely at. One correction: this isn't containers. Each session is a microVM with it
by srini-docker 2mo ago
I work at Docker. Lot of valid and useful feedback here that we're looking closely at.
One correction: this isn't containers. Each session is a microVM with its own kernel on the platform's native hypervisor: Hypervisor.framework, WHP, KVM. We wrote a new VMM (not Firecracker) to make it more effective across platforms.
Explained a bit more here about the architecture and why those choices were made: https://www.docker.com/blog/why-microvms-the-architecture-behind-docker-sandboxes/ https://www.docker.com/blog/why-microvms-the-architecture-be...
- kwakubiney 2mo agoWhy’s it not on Linux? What are the difficulties with that platform?
- cogman10 2mo agoLooks like they do support Ubuntu. Is this open source? Can I install this on a non Ubuntu system?
- aborsy 2mo agoA limited form of it with different syntax comes with Docker Desktop. The sbx tool is not available for non-Ubuntu distributions.
- rocfan 2mo agoCLI works on Fedora. Been using it daily for ~ a week. See repo `docker/sbx-releases`. The `.rpm` there has Rocky Linux in the name but works on Fedora.
- srini-docker 2mo agoLinux is available today (Ubuntu): github.com/docker/sbx-releases. Our webpage showing only brew and winget is on us. For the people upthread who asked about on customization: templates (like snapshotting a running sandbox) and kits (YAML applied at creation like install steps, files, network and credential rules, or define a new agent outright) are the supported path now. It's early but take a look here: https://docs.docker.com/ai/sandboxes/customize/ https://docs.docker.com/ai/sandboxes/customize/ On MCP, since credential handling was mentioned here: the sandbox sees one gateway endpoint, and OAuth tokens stay in the host credential store rather than in the VM. https://docs.docker.com/ai/sandboxes/mcp-gateway/ https://docs.docker.com/ai/sandboxes/mcp-gateway/ All this is early. We're looking at more based on feedback from users like running sandboxes in the background for long-horizon work and a lot more (including what you all raised in the thread here). Keep them coming.
- tacker2000 2mo agoPlease consider adding MacPorts support. Brew is notoriously developer-unfriendly.
- dallen33 2mo agoHow so?
- bmurphy1976 2mo agoThe parent didn't go into any detail. I can. Homebrew has a history of ripping out your foundation underneath you. One day you are on Python 3.8, then next day you are on Python 3.10 and all your packages are broken. MacPorts doesn't do that. Now, whether you should you be using the Homebrew Python is a completely different question. YMMV for other platforms managed via Homebrew. I've traditionally used MacPorts for dev tooling and Homebrew for everything else, but with more aggressive adoption of tooling like uv an nvm I'm not sure the different really matters for me anymore.
- xrisk 2mo agopyenv has been standard tooling for far longer than uv. depending on package manager supplied Python packages only makes sense if you’re running rhel or Debian or something and your application is packaged/deployed/the maintenance path uses dnf/apt. Otherwise you should always use a venv and use an out of package manager update mechanism. Like, in a broader sense, vendoring dependencies only makes sense if you’re shipping an application, not on a dev box.
- tacker2000 2mo agoThis is not about python packages, this is about python itself.
- stavros 2mo ago
- atechboy 2mo agoSo the idea is to give each agent a VM to do several tool calls? or one VM for each tool call?
- theplumber 2mo agoI think the idea is to have the agent run in the VM
- tanepiper 2mo agoI'm very glad this now exists - fwiw almost a decade ago I worked on https://github.com/takeoff-env/takeoff https://github.com/takeoff-env/takeoff as a solution for making it easier for hot reloading your stack which is thankfully redundant today, and funnily enough the list of problems you identify is also something I've been working on. Recently I've also been working on a VM stack for an agentic platform using pre-build images with some cloud injection scripts that simplifies the deployment of a private agentic cluster - in the end I went with full VM with a 4vCpu/8gb for the main agent and 2vCPU/4Gb - only the main agent had docker-in-docker, the rest rootless docker but I agree it's still an elevated risk. I'll definitely have to give this a spin and see if I can simplify it to one larger box with this solution.
- cpburns2009 2mo agoDo you have a strategy for secrets? Such as storing them, or using MitM to inject them (e.g., HTTP API requests)? I've used squid cache in the past, and currently use iron-proxy for this sort of feature.
- mikesir87 2mo agoThe secrets are stored in the OS-specific keychain. When a sandbox starts, the network proxy injects the secret into the request (as auth headers) only when the hostname matches. Read more about the secrets handling here - https://docs.docker.com/ai/sandboxes/security/credentials/ https://docs.docker.com/ai/sandboxes/security/credentials/ Kits provide the ability to also define new credentials and how to inject them into new services (connect to internal systems, etc.).
- Geezus_42 2mo agoSounds like what I'm doing with Nix and MicroVM currently.
- filearts 2mo agoIs there any line of sight to open sourcing the vmm? Is it based on libkrun?
- android_reverse 2mo agoVM? own kernel? I wonder if this could allow to run Waydroid on Windows without the hassle of recompiling WSL kernel with Binder and Docker
- Myzel394 2mo agoWhat is WHP?
- zamadatix 2mo agoWindows Hypervisor Platform, to my understanding. https://learn.microsoft.com/en-us/virtualization/api/hypervisor-platform/hypervisor-platform https://learn.microsoft.com/en-us/virtualization/api/hypervi... https://www.qemu.org/docs/master/system/whpx.html https://www.qemu.org/docs/master/system/whpx.html
- srini-docker 2mo agoYes!
- apitman 2mo agoFun fact: QEMU runs natively on windows and supports acceleration with WHP. It works surprisingly well.
- codethief 2mo ago> supports acceleration with WHP On Windows 11, too? At least for hardware virtualization in VMWare one would have to disable Windows Device Guard & Credential Guard for that.
- bradgessler 2mo agoI'd like to see real numbers that compare Docker Desktop for macOS before microVMs to post-microVMs. I stopped using Docker on macOS because host file system performance was so slow, even with all of the caching hacks piled on top of it, that it made the whole thing effectively unusable for development. Directionally the post shared sounds great, but it seems "too good to be true" that we'd have a performant microVM for macOS.
- exographicskip 2mo agoSame. Been using orbstack for a couple years now
- jbverschoor 2mo agoI wrote https://github.com/jrz/container-shell https://github.com/jrz/container-shell which I use daily for both claude and other things. Compatible with Orbstack
- mooreds 2mo agoWhat about inbound credential checking, for when agent A calls agent B? I looked at the docs last week and didn't see anything about that.
- adityazero 2mo ago[dead]
- Humphrey 2mo agoMy feedback on sbx: Concept is great - works quite well - I often have multiple short lived sandboxes running at once. Docs [1] on overriding auth are incorrect. Sbx ignores inject[].username for basic auth and instead the stored secret needs to be the complete Authorization header. This should be made clear, or fixed. Having to log in every couple of days SUCKS!! Opening the browser so I can login (which we shouldn't have to do) interfers with my scripts that create and destroy sandboxes as I need them. I miss the old worktree functionality - I dislike the new clone concept - So I've created my own scripts that create a worktree for a feature, and run sbx create/run from there. [1] https://docs.docker.com/ai/sandboxes/customize/kit-reference/#apikey https://docs.docker.com/ai/sandboxes/customize/kit-reference...