Today at @WeAreDevs, Docker and the @linuxfoundation are announcing a collaboration around the Docker Sandbox Kit Specification: an open standard for declaring what an agent may do, where it may reach, and what it may touch.
Open source under Apache 2.0.
Read the deep dive:
The panel asked the questions.
This post captures one CISO's perspective on the answers.
Docker CISO Mark Lechner shares why governing agents where devs work, starting from trusted software, and designing for containment beats chasing perfect prevention.
Today's sandbox protects the agent.
Tomorrow's may need to protect the code it writes.
@shelajev talks with Docker Sandboxes PM Eric Jia about where sandboxing is headed and what developers should be preparing for next.