JetBrains' AI coding agent as a mixin — the stable-channel install in an overlay, with the six ...
103
JetBrains' AI coding agent as a mixin — the stable-channel install in an overlay, with the six model-provider credentials Junie can route through and the egress policy they need. Layer it onto a shell base and run `junie`.
| Name | Required | Default | Description |
|---|---|---|---|
build | Optional | 3294.5 | JetBrains build number for that release, the installer's own pin |
version | Optional | 26.9.21 | Junie marketing release, the version the binary reports |
[email protected]| Type | Required | Description | |
|---|---|---|---|
com.docker.sandbox/network-policy@1 | Required | — | |
com.docker.sandbox/credential@1 | Optional | Anthropic API access | |
com.docker.sandbox/credential@1 | Optional | Google Gemini API access | |
com.docker.sandbox/credential@1 | Optional | JetBrains AI / Junie service access | |
com.docker.sandbox/credential@1 | Optional | OpenAI API access | |
com.docker.sandbox/credential@1 | Optional | OpenRouter API access | |
com.docker.sandbox/credential@1 | Optional | xAI API access | |
com.docker.sandbox/agent-context@1 | Required | — | |
sbx run <agent> --kit docker/sbx-kit-junie-mixin:latestRun the following command to install sbx on your machine.
brew install docker/tap/sbxwinget install Docker.sbxNote
Experimental: Sandbox Kit v3This kit uses the experimental Sandbox Kit specification, specifically v3. The format and runtime behavior may change before v3 is stable.
JetBrains' Junie as a kind: mixin kit:
an overlay you layer onto a shell workload, rather than a sandbox image of its
own. The workload form is ../junie.
sbx create --kit docker.io/dockerdev/sbx-kit-shell --kit ./junie-mixin
sbx exec <sandbox> -- sh -lc 'junie'
junie lands at /home/agent/.local/bin/junie, with a shim on PATH at
/usr/local/bin/junie.
Composing this kit and ../junie is refused: both provide junie, and one
capability name has one owner.
A pinned stable-channel Junie install, the six model-provider credentials
Junie can route through (anthropic, google, junie, openai,
openrouter, xai, all optional) and the runtime egress policy they need.
The pin is two args, because JetBrains ships two version numbers: version
(build arg JUNIE_MARKETING_VERSION, e.g. 26.9.21) is the release the
binary reports and what provides: ["junie@<version>"] publishes, and build
(build arg JUNIE_VERSION, e.g. 3294.5) is the JetBrains build number,
which is the only thing install.sh's own documented override accepts. The
overlay asserts junie --version contains both, so they cannot drift apart.
Both must stay equal to the workload's, since the two shapes provide one name.
See ../junie/README.md for how to bump them.
JUNIE_SKIP_UPDATE_CHECK=1 rides in /etc/profile.d/junie-env.sh because a
mixin's image config never becomes the composed image's. That variable is what
seals the shim's auto-update poll, and the egress policy deliberately omits
the hosts the poll would reach — so from a non-login shell the check fails
against a blocked host rather than being skipped. Use sh -lc.
ENTRYPOINT.agent-sessions@1 drives the workload's entrypoint,
which under a mixin is the base's shell. The workload form declares
--task there; here you pass it yourself.agent-context@1's filename is
workload-only, so this kit contributes a body and the base decides which
file the agent reads.Pulls:
57
Last week