Sign inSign up

docker/sbx-kit-copilot-mixin

Verified Publisher

By Docker, Inc.

•Updated 8 days ago

GitHub's Copilot CLI as a mixin — the CLI in an overlay, with the GitHub and Copilot credential...

Sandbox Kit
0

226

docker/sbx-kit-copilot-mixin repository overview

Digest

sha256:39f6cae986d8…

Size

94.4 MB

Schema

v3

Pushed

8 days ago

Specificationspec.yaml

MIXIN

GitHub's Copilot CLI as a mixin — the CLI in an overlay, with the GitHub and Copilot credentials, scoped egress, and the trusted-folder and MCP-gateway seeds the agent needs. Layer it onto a shell base and run `copilot`.


Arguments
NameRequiredDefaultDescription
versionOptional1.0.86

GitHub Copilot CLI release to install



CapabilitiesExpand a row to see its full configuration. See the full spec for the complete descriptor.
TypeRequiredDescription
com.docker.sandbox/network-policy@1Required—
com.docker.sandbox/credential@1OptionalGitHub API access for git and gh
com.docker.sandbox/credential@1OptionalCopilot request access, separable from the broader github token
com.docker.sandbox/lifecycle@1Required—
com.docker.sandbox/agent-context@1Required—

Requiresdeb/jq, deb/util-linux

Apply this mixin to a sandbox

sbx run <agent> --kit docker/sbx-kit-copilot-mixin:latest

Make sure you have docker sbx installed

Run the following command to install sbx on your machine.

macOS
brew install docker/tap/sbx
Windows
winget install Docker.sbx
Learn more about docker sbx⁠

Note

Experimental: Sandbox Kit v3

This kit uses the experimental Sandbox Kit specification⁠, specifically v3⁠. The format and runtime behavior may change before v3 is stable.

⁠copilot-mixin

GitHub's Copilot CLI as a v3 mixin: the same agent the copilot⁠ workload kit ships, packaged as an overlay that lands on a shell base instead of as a root filesystem of its own.

Use this when you want copilot alongside something else — a different base image, another agent, a set of tools — rather than as the sandbox's entire identity. Use copilot⁠ when Copilot is the sandbox.

⁠What it carries

The overlay itself: the CLI tree at /opt/copilot-cli with a /usr/local/bin/copilot shim. Nothing else — the v2 copilot kit declared no environment variables, so unlike the codex and cursor mixins there is no /etc/profile.d drop.

Declaratively it makes the same asks as the workload kit: both credentials (github for git and gh, copilot for a separable fine-grained Copilot PAT), the egress each one injects into, the trusted_folders seed, and the MCP-gateway registration that merges into ~/.copilot/mcp-config.json rather than overwriting it.

⁠What it leaves to the base

  • The launch command. A mixin's image config does not become the composed image's, so there is no entrypoint here — and therefore no --yolo. Pass it yourself if you want it.
  • The AGENTS.md profile. filename is workload-only; this kit contributes a context body and the workload names the profile.
  • The package cache. The copilot kit refreshes its base image's apt cache at boot and allows the mirrors that needs. Which package manager a base ships and which mirrors it trusts are the base's business, so neither the hook nor the mirror hosts are declared here.

The MCP hook needs jq and flock on the base, as it does in the workload kit; a base carrying the platform floor and coreutils has both.

⁠Usage

sbx create --kit ./shell --kit ./copilot-mixin --name my-task /path/to/task

Then run copilot inside the sandbox.

Composing this with the copilot⁠ workload kit is refused: both provide the name copilot, and one capability name has one owner.

⁠References

This week's pulls

Pulls:

76

Last week