sha256:a3bdcc041c802a68ed99e7bbb6ffbf617f1f71dcf2553b072ff87cd0a50511f5
Last pushed
12 days by cdupuis
Type
Sandbox Kit
Manifest digest
sha256:a3bdcc041c802a68ed99e7bbb6ffbf617f1f71dcf2553b072ff87cd0a50511f5
schemaVersion: "3"
displayName: Docker Agent (mixin)
description: Docker Agent as a mixin -- the binary in an overlay at its self-updateable /opt home, with eight optional proxy-managed provider credentials and the egress they need. Layer it onto a shell base and run `docker-agent run`.
sourceUrl: https://github.com/docker/docker-agent
version: 1.0.0
kind: mixin
provides:
- docker-agent
capabilities:
- type: com.docker.sandbox/network-policy@1
config:
runtime:
allow:
- api.anthropic.com
- claude.ai
- console.anthropic.com
- api.business.githubcopilot.com
- api.enterprise.githubcopilot.com
- api.github.com
- api.githubcopilot.com
- api.individual.githubcopilot.com
- copilot.github.com
- github.com
- raw.githubusercontent.com
- aiplatform.googleapis.com
- generativelanguage.googleapis.com
- oauth2.googleapis.com
- vertexai.googleapis.com
- api.openai.com
- openrouter.ai
- objects.githubusercontent.com
- models.dev
- type: com.docker.sandbox/credential@1
optional: true
config:
apiKey:
inject:
- domain: api.anthropic.com
format: '%s'
header: x-api-key
- domain: claude.ai
format: '%s'
header: x-api-key
- domain: console.anthropic.com
format: '%s'
header: x-api-key
name: ANTHROPIC_API_KEY
proxyManaged: true
phase: runtime
service: anthropic
description: Anthropic API access
- type: com.docker.sandbox/credential@1
optional: true
config:
apiKey:
inject:
- domain: api.business.githubcopilot.com
format: Bearer %s
header: Authorization
- domain: api.enterprise.githubcopilot.com
format: Bearer %s
header: Authorization
- domain: api.github.com
format: Bearer %s
header: Authorization
- domain: api.githubcopilot.com
format: Bearer %s
header: Authorization
- domain: api.individual.githubcopilot.com
format: Bearer %s
header: Authorization
- domain: copilot.github.com
format: Bearer %s
header: Authorization
- domain: github.com
format: Bearer %s
header: Authorization
- domain: raw.githubusercontent.com
format: Bearer %s
header: Authorization
phase: runtime
service: github
description: GitHub and Copilot access
- type: com.docker.sandbox/credential@1
optional: true
config:
apiKey:
inject:
- domain: aiplatform.googleapis.com
format: '%s'
header: x-goog-api-key
- domain: generativelanguage.googleapis.com
format: '%s'
header: x-goog-api-key
- domain: oauth2.googleapis.com
format: '%s'
header: x-goog-api-key
- domain: vertexai.googleapis.com
format: '%s'
header: x-goog-api-key
name: GOOGLE_API_KEY
proxyManaged: true
phase: runtime
service: google
description: Google AI API access
- type: com.docker.sandbox/credential@1
optional: true
config:
apiKey:
name: MISTRAL_API_KEY
proxyManaged: true
phase: runtime
service: mistral
description: Mistral API access
- type: com.docker.sandbox/credential@1
optional: true
config:
apiKey:
name: NEBIUS_API_KEY
proxyManaged: true
phase: runtime
service: nebius
description: Nebius API access
- type: com.docker.sandbox/credential@1
optional: true
config:
apiKey:
inject:
- domain: api.openai.com
format: Bearer %s
header: Authorization
name: OPENAI_API_KEY
proxyManaged: true
phase: runtime
service: openai
description: OpenAI API access
- type: com.docker.sandbox/credential@1
optional: true
config:
apiKey:
inject:
- domain: openrouter.ai
format: Bearer %s
header: Authorization
name: OPENROUTER_API_KEY
proxyManaged: true
phase: runtime
service: openrouter
description: OpenRouter API access
- type: com.docker.sandbox/credential@1
optional: true
config:
apiKey:
name: XAI_API_KEY
proxyManaged: true
phase: runtime
service: xai
description: xAI API access
- type: com.docker.sandbox/agent-context@1
config:
contentFile: /usr/share/sandbox/kit/docker-agent-mixin/docker-agent-mixin-context.md
args:
version:
default: ""
description: docker-agent release tag to pin. Empty (the default) resolves the newest release at build time.
buildArg: DOCKER_AGENT_VERSION