AWS's Kiro CLI as a mixin — kiro-cli and its device-flow launcher in an overlay, with the egres...
100
AWS's Kiro CLI as a mixin — kiro-cli and its device-flow launcher in an overlay, with the egress policy Kiro's auth, chat and telemetry backends need and the hooks that set up its state directory and MCP gateway. Layer it onto a shell base and run `kiro`.
kiro| Type | Required | Description | |
|---|---|---|---|
com.docker.sandbox/network-policy@1 | Required | — | |
com.docker.sandbox/lifecycle@1 | Required | — | |
com.docker.sandbox/agent-context@1 | Required | — | |
sbx run <agent> --kit docker/sbx-kit-kiro-mixin:latestRun the following command to install sbx on your machine.
brew install docker/tap/sbxwinget install Docker.sbxNote
Experimental: Sandbox Kit v3This kit uses the experimental Sandbox Kit specification, specifically v3. The format and runtime behavior may change before v3 is stable.
AWS's Kiro CLI as a kind: mixin kit: an
overlay you layer onto a shell workload, rather than a sandbox image of its
own. The workload form is ../kiro.
sbx create --kit docker.io/dockerdev/sbx-kit-shell --kit ./kiro-mixin
sbx exec <sandbox> -- kiro chat --trust-all-tools
Run kiro, not kiro-cli: kiro is the device-flow launcher, which checks
whether you are signed in and starts the login flow if you are not before
handing off. Both land on PATH at /usr/local/bin.
Composing this kit and ../kiro is refused: both provide kiro, and one
capability name has one owner.
kiro-cli and its seeded state, the start.sh device-flow launcher, the egress
policy Kiro's auth, chat and telemetry backends need, and the hooks that re-run
kiro-cli setup at create and register the MCP gateway at boot.
This kit and ../kiro are the exception among the agent kits in this repo:
the others pin their tool and publish provides: ["<tool>@<version>"], while
kiro's provides: ["kiro"] stays unversioned, because the install cannot be
pinned. The installer's whole option surface is --help and
--channel CHANNEL, parse_args refuses anything else, it reads no version
from the environment, and the URLs it builds spell the release as the literal
latest. Versioned archives exist but no versioned manifest does, so a pinned
download would lose the checksum verification the current install has. The
full evidence, and the cost of leaving it unversioned, is in
../kiro/README.md.
Kiro has no API-key path, so this kit declares no credential — there is nothing for the host's store to hold and nothing for the proxy to inject. The first run opens a device flow that needs a human with a browser. That is also why there are no session verbs on either form of this kit.
ENTRYPOINT; chat --trust-all-tools are yours to pass rather than the kit's to bake.agent-context@1's filename is
workload-only, so this kit contributes a body; the workload form owns
KIRO.md.IS_SANDBOX=1 rides in /etc/profile.d/kiro-env.sh instead of ENV.start.shstart.sh is a copy of ../kiro/start.sh, not a reference
to it: a kit's build context is rooted at its own descriptor's directory and
may not escape it, so a sibling kit's assets are unreachable from this recipe.
The two copies must be changed together.
Pulls:
58
Last week