Sign inSign up

docker/sbx-kit-crush-mixin

Verified Publisher

By Docker, Inc.

•Updated 8 days ago

Charm's multi-provider AI coding agent as a mixin -- the Crush binary in an overlay, with proxy-m...

Sandbox Kit
0

195

docker/sbx-kit-crush-mixin repository overview

Digest

sha256:e8268f2ad62e…

Size

24.8 MB

Schema

v3

Pushed

8 days ago

Specificationspec.yaml

MIXIN

Charm's multi-provider AI coding agent as a mixin -- the Crush binary in an overlay, with proxy-mediated auth for 15 model providers and the egress they need. Layer it onto a shell base and run `crush`.


Arguments
NameRequiredDefaultDescription
versionOptional0.95.0

Crush release to install from Charm's apt repository



CapabilitiesExpand a row to see its full configuration. See the full spec for the complete descriptor.
TypeRequiredDescription
com.docker.sandbox/network-policy@1Required—
com.docker.sandbox/credential@1OptionalAnthropic API access
com.docker.sandbox/credential@1OptionalAWS Bedrock access
com.docker.sandbox/credential@1OptionalAzure OpenAI access
com.docker.sandbox/credential@1OptionalCerebras API access
com.docker.sandbox/credential@1OptionalGoogle AI API access
com.docker.sandbox/credential@1OptionalGroq API access
com.docker.sandbox/credential@1OptionalHugging Face inference access
com.docker.sandbox/credential@1Optionalio.net API access
com.docker.sandbox/credential@1OptionalMiniMax API access
com.docker.sandbox/credential@1OptionalMistral API access
com.docker.sandbox/credential@1OptionalOpenAI API access
com.docker.sandbox/credential@1OptionalOpenRouter API access
com.docker.sandbox/credential@1OptionalSynthetic API access
com.docker.sandbox/credential@1OptionalVercel v0 API access
com.docker.sandbox/credential@1OptionalZ.ai API access
com.docker.sandbox/agent-context@1Required—

Apply this mixin to a sandbox

sbx run <agent> --kit docker/sbx-kit-crush-mixin:latest

Make sure you have docker sbx installed

Run the following command to install sbx on your machine.

macOS
brew install docker/tap/sbx
Windows
winget install Docker.sbx
Learn more about docker sbx⁠

Note

Experimental: Sandbox Kit v3

This kit uses the experimental Sandbox Kit specification⁠, specifically v3⁠. The format and runtime behavior may change before v3 is stable.

⁠crush-mixin

The mixin form of the crush⁠ kit: Crush⁠ in an overlay that lands on a shell workload, instead of a whole sandbox of its own.

⁠What it is

A kind: mixin kit carrying the Crush binary as a filesystem delta, with the same declarations the workload makes — fifteen optional proxy-managed provider credentials and the runtime allow list covering exactly the hosts they inject into, Bedrock regions enumerated because the allow grammar has no middle-position wildcard.

Crush installs from Charm's apt repository, which is the case where relocation is not available at all: apt-get --root wants its own dpkg database, keyring trust and a bootstrapped base under the target root. So crush-mixin.dockerfile runs the unmodified apt install in a build stage on the workload's own base and carries out exactly the paths dpkg -L crush reports, via tar so modes and symlinks survive. Reading the package's file list rather than hard-coding a prefix means a Charm packaging change that moved the binary fails the build instead of producing an empty overlay.

⁠Compose it

$ sbx create --kit <shell-workload> --kit ./crush-mixin
$ crush --yolo

⁠What it leaves to the base

  • The launch command. No ENTRYPOINT: the base workload's stays, and crush is something you run from its shell — which is also where --yolo, carried by the standalone kit's CMD, has to be passed by hand.
  • agent-sessions@1. The session verbs append to the workload's launch argv, and that is the base's shell here, not Crush. The standalone crush⁠ kit is the one that declares them.
  • The AGENTS.md profile, sbx@1 and the sandbox identity, and the platform floor — bash, the agent user, git, a CA store.

crush and crush-mixin both provide crush, so they are alternatives: composing the two together is refused, one capability having one provider.

This week's pulls

Pulls:

78

Last week