Sign inSign up

docker/sbx-kit-codex-mixin

Verified Publisher

By Docker, Inc.

•Updated 2 days ago

OpenAI's Codex CLI as a mixin — the CLI in an overlay, with the OpenAI credential (API key or C...

Sandbox Kit
Image
0

1.7K

docker/sbx-kit-codex-mixin repository overview

Digest

sha256:be9a4a6c62e9…

Size

156.4 MB

Schema

v3

Pushed

2 days ago

Specificationspec.yaml

MIXIN

OpenAI's Codex CLI as a mixin — the native binary in an overlay, with the OpenAI credential (API key or ChatGPT OAuth) and the hooks the agent needs. Layer it onto a shell base and run `codex`.


Arguments
NameRequiredDefaultDescription
modelOptional

Codex model to use (config.toml `model`); empty keeps the CLI default

reasoningEffortOptional

Reasoning effort (config.toml `model_reasoning_effort`); empty keeps the CLI default

versionOptional0.159.2

Codex CLI release to install



CapabilitiesExpand a row to see its full configuration. See the full spec for the complete descriptor.
TypeRequiredDescription
com.docker.sandbox/network-policy@1Required—
com.docker.sandbox/credential@1OptionalOpenAI API access (API key or ChatGPT OAuth)
com.docker.sandbox/lifecycle@1Required—
com.docker.sandbox/agent-skills@1Optional—
com.docker.sandbox/agent-context@1Required—

Apply this mixin to a sandbox

sbx run <agent> --kit docker/sbx-kit-codex-mixin:latest

Make sure you have docker sbx installed

Run the following command to install sbx on your machine.

macOS
brew install docker/tap/sbx
Windows
winget install Docker.sbx
Learn more about docker sbx⁠

Note

Experimental: Sandbox Kit v3

This kit uses the experimental Sandbox Kit specification⁠, specifically v3⁠. The format and runtime behavior may change before v3 is stable.

⁠codex-mixin

The OpenAI Codex CLI as a v3 mixin: the same agent the codex⁠ workload kit ships, packaged as an overlay that lands on a shell base instead of as a root filesystem of its own.

Use this when you want Codex alongside something else — a different base image, another agent, a set of tools — rather than as the sandbox's entire identity. Use codex⁠ when Codex is the sandbox.

⁠What it carries

The overlay itself: the Codex CLI at /usr/local/bin/codex, xdg-open for the BROWSER export, the /usr/local/share/npm-global/bin/codex shim that codex-app-server⁠'s wrapper execs, and /etc/profile.d/codex-env.sh carrying BROWSER, CODEX_HOME and GIT_TERMINAL_PROMPT.

Declaratively it makes the same asks as the workload kit: the OpenAI credential (API key or ChatGPT OAuth), the egress Codex needs, the ~/.codex/config.toml and ~/.codex/auth.json seeds, the MCP-gateway registration, and the ~/.agents/skills mount point.

It provides: ["codex"], so the mixins that ask for a Codex — codex-acp⁠ and codex-app-server⁠ — resolve against it exactly as they do against the workload kit.

⁠What it leaves to the base

  • The launch command. A mixin's image config does not become the composed image's, so there is no entrypoint here. The base workload's launch command stays, and you run codex from the shell.
  • The AGENTS.md profile. filename is workload-only; this kit contributes a context body and the workload names the profile.
  • The package cache. The codex kit refreshes its base image's apt cache at boot and allows the mirrors that needs. Which package manager a base ships and which mirrors it trusts are the base's business, so neither the hook nor the mirror hosts are declared here.

⁠Usage

sbx create --kit ./shell --kit ./codex-mixin --name my-task /path/to/task

Then run codex inside the sandbox.

Composing this with the codex⁠ workload kit is refused: both provide the name codex, and one capability name has one owner.

⁠References

This week's pulls

Pulls:

460

Last week