Sign inSign up

docker/sbx-kit-docker-agent-mixin:latest

Multi-platform
Manifest digest

sha256:e9a19ac85aa971a2e380b0317f17b6d242404b80dd32d17f1b19fec3d2d7758e

Last pushed

8 days by cdupuis

Type

Sandbox Kit

Manifest digest

sha256:e9a19ac85aa971a2e380b0317f17b6d242404b80dd32d17f1b19fec3d2d7758e

yaml
schemaVersion: "3"
displayName: Docker Agent (mixin)
description: Docker Agent as a mixin -- the binary in an overlay at its self-updateable /opt home, with eight optional proxy-managed provider credentials and the egress they need. Layer it onto a shell base and run `docker-agent run`.
sourceUrl: https://github.com/docker/docker-agent
version: 1.141.0
kind: mixin
provides:
    - [email protected]
capabilities:
    - type: com.docker.sandbox/network-policy@1
      config:
        runtime:
            allow:
                - api.anthropic.com
                - claude.ai
                - console.anthropic.com
                - api.business.githubcopilot.com
                - api.enterprise.githubcopilot.com
                - api.github.com
                - api.githubcopilot.com
                - api.individual.githubcopilot.com
                - copilot.github.com
                - github.com
                - raw.githubusercontent.com
                - aiplatform.googleapis.com
                - generativelanguage.googleapis.com
                - oauth2.googleapis.com
                - vertexai.googleapis.com
                - api.openai.com
                - openrouter.ai
                - objects.githubusercontent.com
                - models.dev
    - type: com.docker.sandbox/credential@1
      optional: true
      config:
        apiKey:
            inject:
                - domain: api.anthropic.com
                  format: '%s'
                  header: x-api-key
                - domain: claude.ai
                  format: '%s'
                  header: x-api-key
                - domain: console.anthropic.com
                  format: '%s'
                  header: x-api-key
            name: ANTHROPIC_API_KEY
            proxyManaged: true
        phase: runtime
        service: anthropic
      description: Anthropic API access
    - type: com.docker.sandbox/credential@1
      optional: true
      config:
        apiKey:
            inject:
                - domain: api.business.githubcopilot.com
                  format: Bearer %s
                  header: Authorization
                - domain: api.enterprise.githubcopilot.com
                  format: Bearer %s
                  header: Authorization
                - domain: api.github.com
                  format: Bearer %s
                  header: Authorization
                - domain: api.githubcopilot.com
                  format: Bearer %s
                  header: Authorization
                - domain: api.individual.githubcopilot.com
                  format: Bearer %s
                  header: Authorization
                - domain: copilot.github.com
                  format: Bearer %s
                  header: Authorization
                - domain: github.com
                  format: Bearer %s
                  header: Authorization
                - domain: raw.githubusercontent.com
                  format: Bearer %s
                  header: Authorization
        phase: runtime
        service: github
      description: GitHub and Copilot access
    - type: com.docker.sandbox/credential@1
      optional: true
      config:
        apiKey:
            inject:
                - domain: aiplatform.googleapis.com
                  format: '%s'
                  header: x-goog-api-key
                - domain: generativelanguage.googleapis.com
                  format: '%s'
                  header: x-goog-api-key
                - domain: oauth2.googleapis.com
                  format: '%s'
                  header: x-goog-api-key
                - domain: vertexai.googleapis.com
                  format: '%s'
                  header: x-goog-api-key
            name: GOOGLE_API_KEY
            proxyManaged: true
        phase: runtime
        service: google
      description: Google AI API access
    - type: com.docker.sandbox/credential@1
      optional: true
      config:
        apiKey:
            name: MISTRAL_API_KEY
            proxyManaged: true
        phase: runtime
        service: mistral
      description: Mistral API access
    - type: com.docker.sandbox/credential@1
      optional: true
      config:
        apiKey:
            name: NEBIUS_API_KEY
            proxyManaged: true
        phase: runtime
        service: nebius
      description: Nebius API access
    - type: com.docker.sandbox/credential@1
      optional: true
      config:
        apiKey:
            inject:
                - domain: api.openai.com
                  format: Bearer %s
                  header: Authorization
            name: OPENAI_API_KEY
            proxyManaged: true
        phase: runtime
        service: openai
      description: OpenAI API access
    - type: com.docker.sandbox/credential@1
      optional: true
      config:
        apiKey:
            inject:
                - domain: openrouter.ai
                  format: Bearer %s
                  header: Authorization
            name: OPENROUTER_API_KEY
            proxyManaged: true
        phase: runtime
        service: openrouter
      description: OpenRouter API access
    - type: com.docker.sandbox/credential@1
      optional: true
      config:
        apiKey:
            name: XAI_API_KEY
            proxyManaged: true
        phase: runtime
        service: xai
      description: xAI API access
    - type: com.docker.sandbox/agent-context@1
      config:
        contentFile: /usr/share/sandbox/kit/docker-agent-mixin/docker-agent-mixin-context.md
args:
    version:
        default: 1.141.0
        description: docker-agent release to install, without the tag's `v` prefix.
        pattern: ^[0-9]+\.[0-9]+\.[0-9]+$
        buildArg: DOCKER_AGENT_VERSION