What happened
- On September 24, Docker released Cloud Sandboxes, the version on its own infrastructure of the isolated environments it already offered for the local computer, according to the announcement signed by Timir Karia and Srini Sekaran. The
sbx movecommand captures the environment’s file system and recreates it on the other side, in both directions. - Each environment is a microVM with its own network and its own secrets. Keys are stored once and a proxy injects them per request, so the agent never has them in view.
- Pricing is metered per second of compute: $0.07 an hour for 1 vCPU and 2 GiB, $0.14 for the default configuration of 2 vCPU and 4 GiB, and up to $1.12 for 16 vCPU and 32 GiB. Volumes, egress traffic and image publishing aren’t charged, and a paused environment costs nothing.
- Environments run for one hour by default and up to 24 hours per session. New accounts get $250 in credit. The same day, the company announced it is bringing the specification for these environments to the CNCF as an open standard for agent permissions.
Why it matters
- A small team in Chile can run coding agents for hours without its own servers and with a spending cap measured in seconds. The barrier to entry for autonomous work drops to a credit card.
- The secrets design is the interesting part: a prompt injection can’t extract a key the agent never had. It’s a structural defense, not a behavioral rule, which is the only kind of defense that survives a model that makes mistakes.
- The flip side is that the project’s code, credentials and traffic pass through a third party’s infrastructure. For personal data under Law 21.719, that means looking at the data processing agreement before the price.
The number
24 hours is the maximum an environment can run per session.
Context
Monitoring agents inside the company has already moved capital: Island raised $400 million to control them from the browser. And the risk this design tries to close is the same one documented when an assistant combines private data, untrusted content and a way out.
What’s next
- Centralized governance for enterprises is announced within Docker AI Governance, with no date: as of September 26, 2026, the announcement just says “coming soon.”
- The $250 credit for new accounts is described as a limited-time offer, with no published end date.
- The specification handed to the CNCF has no date for adoption as a standard.
Bottom line
The industry spent a year debating how much an agent can be allowed to do. The answer that’s taking hold isn’t a written policy; it’s a machine that switches itself off after 24 hours.
Sources
- Introducing Cloud Sandboxes: Start on Your Laptop, Finish in the Cloud, Docker blog, September 24, 2026.
- Docker and CNCF partner on an open spec for agent permissions, Docker blog, September 24, 2026.
Edited by Rodrigo Cornejo. How we select and verify: who writes these notes.


