Sign inSign up

docker/sbx-kit-droid-mixin

Verified Publisher

By Docker, Inc.

•Updated 9 days ago

Factory's Droid CLI as a mixin — the upstream install in an overlay, with the Factory credentia...

Sandbox Kit
0

84

docker/sbx-kit-droid-mixin repository overview

Digest

sha256:f3ba7491a5b1…

Size

110.1 MB

Schema

v3

Pushed

9 days ago

Specificationspec.yaml

MIXIN

Factory's Droid CLI as a mixin — the upstream install in an overlay, with the Factory credential (API key or WorkOS OAuth), the egress policy the agent needs, and the hooks that prepare its state directory. Layer it onto a shell base and run `droid`.


Arguments
NameRequiredDefaultDescription
versionOptional0.223.0

Droid release to install



CapabilitiesExpand a row to see its full configuration. See the full spec for the complete descriptor.
TypeRequiredDescription
com.docker.sandbox/network-policy@1Required—
com.docker.sandbox/credential@1RequiredFactory API access for Droid (API key or WorkOS OAuth)
com.docker.sandbox/lifecycle@1Required—
com.docker.sandbox/agent-context@1Required—

Apply this mixin to a sandbox

sbx run <agent> --kit docker/sbx-kit-droid-mixin:latest

Make sure you have docker sbx installed

Run the following command to install sbx on your machine.

macOS
brew install docker/tap/sbx
Windows
winget install Docker.sbx
Learn more about docker sbx⁠

Note

Experimental: Sandbox Kit v3

This kit uses the experimental Sandbox Kit specification⁠, specifically v3⁠. The format and runtime behavior may change before v3 is stable.

⁠droid-mixin

Factory's Droid CLI⁠ as a kind: mixin kit: an overlay you layer onto a shell workload, rather than a sandbox image of its own. The workload form is ../droid⁠.

⁠Compose it

sbx create --kit docker.io/dockerdev/sbx-kit-shell --kit ./droid-mixin
sbx exec <sandbox> -- droid

droid lands at /home/agent/.local/bin/droid, with a shim on PATH at /usr/local/bin/droid so it resolves on any base.

Composing this kit and ../droid is refused: both provide droid, and one capability name has one owner.

⁠What it carries

The same declarations as the workload — the droid credential (API key or WorkOS OAuth), the egress policy for Factory's hosts, and the install hook that prepares ~/.factory.

The same pin, too. version (build arg DROID_VERSION) is the Droid release the overlay installs, expanded into provides: ["droid@<version>"], and it must stay equal to the workload's, since the two shapes provide one name. Factory's curl | sh installer takes no version — VER="0.223.0" is a plain literal and the script reads neither $@ nor the environment — so the overlay fetches the pinned artifact from the installer's own versioned URL template and verifies its published .sha256, then asserts the binary reports the declared release. See ../droid/README.md⁠ for the detail and for how to bump it.

⁠What it leaves to the base

  • The launch command. The mixin sets no ENTRYPOINT; the base workload's entrypoint stays and you run droid from the shell.
  • The context-file profile. agent-context@1's filename is workload-only, so this kit contributes a body (droid-mixin-context.md⁠) and the base decides which profile file the agent reads.
  • The platform floor and identity. sbx@1 is a workload declaration: a mixin's image config never becomes the composed image's, so the base's shell, user and workspace are the ones in play.

This week's pulls

Pulls:

55

Last week