Sign inSign up

docker/sbx-kit-junie-mixin

Verified Publisher

By Docker, Inc.

•Updated 9 days ago

JetBrains' AI coding agent as a mixin — the stable-channel install in an overlay, with the six ...

Sandbox Kit
0

103

docker/sbx-kit-junie-mixin repository overview

Digest

sha256:8f39aed0f43f…

Size

317.7 MB

Schema

v3

Pushed

9 days ago

Specificationspec.yaml

MIXIN

JetBrains' AI coding agent as a mixin — the stable-channel install in an overlay, with the six model-provider credentials Junie can route through and the egress policy they need. Layer it onto a shell base and run `junie`.


Arguments
NameRequiredDefaultDescription
buildOptional3294.5

JetBrains build number for that release, the installer's own pin

versionOptional26.9.21

Junie marketing release, the version the binary reports



CapabilitiesExpand a row to see its full configuration. See the full spec for the complete descriptor.
TypeRequiredDescription
com.docker.sandbox/network-policy@1Required—
com.docker.sandbox/credential@1OptionalAnthropic API access
com.docker.sandbox/credential@1OptionalGoogle Gemini API access
com.docker.sandbox/credential@1OptionalJetBrains AI / Junie service access
com.docker.sandbox/credential@1OptionalOpenAI API access
com.docker.sandbox/credential@1OptionalOpenRouter API access
com.docker.sandbox/credential@1OptionalxAI API access
com.docker.sandbox/agent-context@1Required—

Apply this mixin to a sandbox

sbx run <agent> --kit docker/sbx-kit-junie-mixin:latest

Make sure you have docker sbx installed

Run the following command to install sbx on your machine.

macOS
brew install docker/tap/sbx
Windows
winget install Docker.sbx
Learn more about docker sbx⁠

Note

Experimental: Sandbox Kit v3

This kit uses the experimental Sandbox Kit specification⁠, specifically v3⁠. The format and runtime behavior may change before v3 is stable.

⁠junie-mixin

JetBrains' Junie⁠ as a kind: mixin kit: an overlay you layer onto a shell workload, rather than a sandbox image of its own. The workload form is ../junie⁠.

⁠Compose it

sbx create --kit docker.io/dockerdev/sbx-kit-shell --kit ./junie-mixin
sbx exec <sandbox> -- sh -lc 'junie'

junie lands at /home/agent/.local/bin/junie, with a shim on PATH at /usr/local/bin/junie.

Composing this kit and ../junie is refused: both provide junie, and one capability name has one owner.

⁠What it carries

A pinned stable-channel Junie install, the six model-provider credentials Junie can route through (anthropic, google, junie, openai, openrouter, xai, all optional) and the runtime egress policy they need.

The pin is two args, because JetBrains ships two version numbers: version (build arg JUNIE_MARKETING_VERSION, e.g. 26.9.21) is the release the binary reports and what provides: ["junie@<version>"] publishes, and build (build arg JUNIE_VERSION, e.g. 3294.5) is the JetBrains build number, which is the only thing install.sh's own documented override accepts. The overlay asserts junie --version contains both, so they cannot drift apart. Both must stay equal to the workload's, since the two shapes provide one name. See ../junie/README.md⁠ for how to bump them.

⁠Prefer a login shell

JUNIE_SKIP_UPDATE_CHECK=1 rides in /etc/profile.d/junie-env.sh because a mixin's image config never becomes the composed image's. That variable is what seals the shim's auto-update poll, and the egress policy deliberately omits the hosts the poll would reach — so from a non-login shell the check fails against a blocked host rather than being skipped. Use sh -lc.

⁠What it leaves to the base

  • The launch command. The mixin sets no ENTRYPOINT.
  • No session verbs. agent-sessions@1 drives the workload's entrypoint, which under a mixin is the base's shell. The workload form declares --task there; here you pass it yourself.
  • The context-file profile. agent-context@1's filename is workload-only, so this kit contributes a body and the base decides which file the agent reads.

This week's pulls

Pulls:

57

Last week