| ▲ | McScrooge 5 hours ago | ||||||||||||||||
https://docker.github.io/docker-agent/configuration/sandbox/ If, like me, you couldn't find any security-related info on the linked page. | |||||||||||||||||
| ▲ | gregwebs 3 hours ago | parent | next [-] | ||||||||||||||||
Docker Agent is a harness. There is a sandbox mode that can be used to run it in docker sandbox (a VM, not a container). If you don't use sandbox mode then I assume it is running in a container. If you don't want to use their harness then you wouldn't use docker agent and instead use their `sbx` cli to run the harness of your choice (claude, codex, pi, etc). I think it will be great if Docker can get people used to using secure VMs. I am developing a similar project (still a work in progress): https://github.com/gregwebs/agent-vm | |||||||||||||||||
| |||||||||||||||||
| ▲ | ShinyLeftPad 4 hours ago | parent | prev [-] | ||||||||||||||||
i remember going through the entire docs of docker sandbox and there was not one mention of attack vectors. did they fix that? | |||||||||||||||||
| |||||||||||||||||