xAI's terminal-based coding agent as a mixin — the CLI in an overlay, with the xAI credential a...
102
xAI's terminal-based coding agent as a mixin — the CLI in an overlay, with the xAI credential and the egress policy Grok's login and inference need. Layer it onto a shell base and run `grok`.
| Name | Required | Default | Description |
|---|---|---|---|
version | Optional | 1.0.34 | Grok release to install |
[email protected]| Type | Required | Description | |
|---|---|---|---|
com.docker.sandbox/network-policy@1 | Required | — | |
com.docker.sandbox/credential@1 | Optional | xAI API access for Grok | |
com.docker.sandbox/agent-context@1 | Required | — | |
sbx run <agent> --kit docker/sbx-kit-grok-mixin:latestRun the following command to install sbx on your machine.
brew install docker/tap/sbxwinget install Docker.sbxNote
Experimental: Sandbox Kit v3This kit uses the experimental Sandbox Kit specification, specifically v3. The format and runtime behavior may change before v3 is stable.
xAI's Grok Build as a kind: mixin
kit: an overlay you layer onto a shell workload, rather than a sandbox image
of its own. The workload form is ../grok.
sbx create --kit docker.io/dockerdev/sbx-kit-shell --kit ./grok-mixin
sbx exec <sandbox> -- grok --yolo
grok lands at /home/agent/.local/bin/grok, with a shim on PATH at
/usr/local/bin/grok so it resolves on any base.
Composing this kit and ../grok is refused: both provide grok, and one
capability name has one owner.
The xai credential (XAI_API_KEY, injected as a bearer token on requests to
api.x.ai) and the runtime egress policy Grok's login and inference need —
api.x.ai, auth.x.ai, cli-chat-proxy.grok.com.
../grok into its own root
filesystem, this kit into an overlay. So there is no install hook, and x.ai
is not in the egress policy at all — nothing inside the sandbox reaches it.version arg carries
the Grok release, the recipe passes it to install.sh as its one positional
argument, and the kit publishes provides: ["grok@<version>"] plus a
top-level version: from that arg — so a kit asking for grok >= 1 can
resolve against it. The build runs grok --version and fails if the installed
binary reports anything else. curl -fsSL https://x.ai/cli/stable returns the
current release; bump this kit and ../grok together, since both provide the
name grok and must name the same release.ENTRYPOINT, so --yolo and
--no-auto-update are yours to pass rather than the kit's to bake.agent-sessions@1 drives the workload's entrypoint,
which under a mixin is the base's shell.agent-context@1's filename is workload-only, so this kit
contributes a body and the base decides which file the agent reads.Pulls:
62
Last week