Sign inSign up

docker/sbx-kit-docker-agent-mixin:1.0.0

Multi-platform
Manifest digest

sha256:a3bdcc041c802a68ed99e7bbb6ffbf617f1f71dcf2553b072ff87cd0a50511f5

Last pushed

12 days by cdupuis

Type

Sandbox Kit

Manifest digest

sha256:a3bdcc041c802a68ed99e7bbb6ffbf617f1f71dcf2553b072ff87cd0a50511f5

yaml
schemaVersion: "3"
displayName: Docker Agent (mixin)
description: Docker Agent as a mixin -- the binary in an overlay at its self-updateable /opt home, with eight optional proxy-managed provider credentials and the egress they need. Layer it onto a shell base and run `docker-agent run`.
sourceUrl: https://github.com/docker/docker-agent
version: 1.0.0
kind: mixin
provides:
    - docker-agent
capabilities:
    - type: com.docker.sandbox/network-policy@1
      config:
        runtime:
            allow:
                - api.anthropic.com
                - claude.ai
                - console.anthropic.com
                - api.business.githubcopilot.com
                - api.enterprise.githubcopilot.com
                - api.github.com
                - api.githubcopilot.com
                - api.individual.githubcopilot.com
                - copilot.github.com
                - github.com
                - raw.githubusercontent.com
                - aiplatform.googleapis.com
                - generativelanguage.googleapis.com
                - oauth2.googleapis.com
                - vertexai.googleapis.com
                - api.openai.com
                - openrouter.ai
                - objects.githubusercontent.com
                - models.dev
    - type: com.docker.sandbox/credential@1
      optional: true
      config:
        apiKey:
            inject:
                - domain: api.anthropic.com
                  format: '%s'
                  header: x-api-key
                - domain: claude.ai
                  format: '%s'
                  header: x-api-key
                - domain: console.anthropic.com
                  format: '%s'
                  header: x-api-key
            name: ANTHROPIC_API_KEY
            proxyManaged: true
        phase: runtime
        service: anthropic
      description: Anthropic API access
    - type: com.docker.sandbox/credential@1
      optional: true
      config:
        apiKey:
            inject:
                - domain: api.business.githubcopilot.com
                  format: Bearer %s
                  header: Authorization
                - domain: api.enterprise.githubcopilot.com
                  format: Bearer %s
                  header: Authorization
                - domain: api.github.com
                  format: Bearer %s
                  header: Authorization
                - domain: api.githubcopilot.com
                  format: Bearer %s
                  header: Authorization
                - domain: api.individual.githubcopilot.com
                  format: Bearer %s
                  header: Authorization
                - domain: copilot.github.com
                  format: Bearer %s
                  header: Authorization
                - domain: github.com
                  format: Bearer %s
                  header: Authorization
                - domain: raw.githubusercontent.com
                  format: Bearer %s
                  header: Authorization
        phase: runtime
        service: github
      description: GitHub and Copilot access
    - type: com.docker.sandbox/credential@1
      optional: true
      config:
        apiKey:
            inject:
                - domain: aiplatform.googleapis.com
                  format: '%s'
                  header: x-goog-api-key
                - domain: generativelanguage.googleapis.com
                  format: '%s'
                  header: x-goog-api-key
                - domain: oauth2.googleapis.com
                  format: '%s'
                  header: x-goog-api-key
                - domain: vertexai.googleapis.com
                  format: '%s'
                  header: x-goog-api-key
            name: GOOGLE_API_KEY
            proxyManaged: true
        phase: runtime
        service: google
      description: Google AI API access
    - type: com.docker.sandbox/credential@1
      optional: true
      config:
        apiKey:
            name: MISTRAL_API_KEY
            proxyManaged: true
        phase: runtime
        service: mistral
      description: Mistral API access
    - type: com.docker.sandbox/credential@1
      optional: true
      config:
        apiKey:
            name: NEBIUS_API_KEY
            proxyManaged: true
        phase: runtime
        service: nebius
      description: Nebius API access
    - type: com.docker.sandbox/credential@1
      optional: true
      config:
        apiKey:
            inject:
                - domain: api.openai.com
                  format: Bearer %s
                  header: Authorization
            name: OPENAI_API_KEY
            proxyManaged: true
        phase: runtime
        service: openai
      description: OpenAI API access
    - type: com.docker.sandbox/credential@1
      optional: true
      config:
        apiKey:
            inject:
                - domain: openrouter.ai
                  format: Bearer %s
                  header: Authorization
            name: OPENROUTER_API_KEY
            proxyManaged: true
        phase: runtime
        service: openrouter
      description: OpenRouter API access
    - type: com.docker.sandbox/credential@1
      optional: true
      config:
        apiKey:
            name: XAI_API_KEY
            proxyManaged: true
        phase: runtime
        service: xai
      description: xAI API access
    - type: com.docker.sandbox/agent-context@1
      config:
        contentFile: /usr/share/sandbox/kit/docker-agent-mixin/docker-agent-mixin-context.md
args:
    version:
        default: ""
        description: docker-agent release tag to pin. Empty (the default) resolves the newest release at build time.
        buildArg: DOCKER_AGENT_VERSION