sha256:ceaffbc5a76634d47655b53b210fe52edcc82f0549ac0c2a2a21fe694370bc95
Last pushed
3 days by michaelirwin244
Type
Sandbox Kit
Manifest digest
sha256:ceaffbc5a76634d47655b53b210fe52edcc82f0549ac0c2a2a21fe694370bc95
schemaVersion: "3"
displayName: Image Cache
description: Preloads container images into the sandbox's Docker engine from the host-side kit registry, so `docker run postgres:16` starts without a Docker Hub round trip. Proof of concept — see README.md for the threat model.
sourceUrl: https://github.com/docker/sandbox-kit-spec
version: 0.1.0
kind: mixin
provides:
- [email protected]
capabilities:
- type: com.docker.sandbox/kit-registry@1
description: Pull preloaded images from (and optionally push them to) the host's image cache
- type: com.docker.sandbox/network-policy@1
optional: true
config:
runtime:
allow:
- registry-1.docker.io
- auth.docker.io
- production.cloudflare.docker.com
- type: com.docker.sandbox/lifecycle@1
config:
startup:
- background: false
command:
- /usr/local/bin/sbx-image-cache
description: Preload images from the host kit registry into the sandbox engine
env:
- SBX_KIT_REGISTRY_URL
- SBX_IMAGE_CACHE_IMAGES
- SBX_IMAGE_CACHE_WRITE_BACK
- SBX_IMAGE_CACHE_WAIT
- DOCKER_HOST
user: "0"
- type: com.docker.sandbox/agent-context@1
config:
content: |
## Preloaded container images
These images were preloaded into this sandbox's Docker engine at boot
and can be used without pulling: `${{ kit.args.images }}`.
Prefer them as-is (don't add `--pull always`). The preload log is
/var/log/sbx-image-cache.log.
args:
images:
default: ""
description: Comma- or space-separated image references to preload (e.g. postgres:16,redis:7)
pattern: ^[A-Za-z0-9._/:@+, -]*$
env: SBX_IMAGE_CACHE_IMAGES
wait:
default: "true"
description: Block boot until preloading finishes
enum:
- "false"
- "true"
env: SBX_IMAGE_CACHE_WAIT
writeBack:
default: "false"
description: On a cache miss, push the upstream pull back into the host cache (shared with other sandboxes)
enum:
- "false"
- "true"
env: SBX_IMAGE_CACHE_WRITE_BACK