nanobot as a mixin -- the agent's own uv tool installation in an overlay, with the proxy-managed ...
102
nanobot as a mixin -- the agent's own uv tool installation in an overlay, with the proxy-managed Anthropic credential, the chat-platform egress and the preconfigured provider config. Layer it onto a shell base and run `nanobot`.
| Name | Required | Default | Description |
|---|---|---|---|
version | Optional | 0.3.5 | nanobot-ai release to install from PyPI |
[email protected]| Type | Required | Description | |
|---|---|---|---|
com.docker.sandbox/network-policy@1 | Required | — | |
com.docker.sandbox/credential@1 | Optional | Anthropic API access | |
com.docker.sandbox/agent-context@1 | Required | — | |
sbx run <agent> --kit docker/sbx-kit-nanobot-mixin:latestRun the following command to install sbx on your machine.
brew install docker/tap/sbxwinget install Docker.sbxNote
Experimental: Sandbox Kit v3This kit uses the experimental Sandbox Kit specification, specifically v3. The format and runtime behavior may change before v3 is stable.
nanobot as a mixin — the same agent
as the nanobot workload kit, packaged as an overlay you layer
onto a shell base instead of running as the sandbox's own image.
sbx run --kit ./nanobot-mixin/ <shell-workload>
Or from a git URL targeting this repo:
sbx run --kit "git+https://github.com/docker/sbx-kits-contrib.git#dir=nanobot-mixin" <shell-workload>
The base workload keeps its own launch command, so nothing starts nanobot for you. Run it from the shell:
nanobot agent --config /home/agent/.nanobot/config.json
uv tool install of nanobot-ai, copied out of a build stage on the
same base the workload uses. The install cannot be relocated (uv bakes
absolute interpreter paths into the venv it creates), so the overlay lands
the tree at the path it was built at./home/agent/.nanobot/config.json, preconfigured for Anthropic through the
sandbox proxy.anthropic credential, the chat-platform and PyPI egress,
and NANOBOT_AGENTS__DEFAULTS__WORKSPACE (as a profile.d export — a
mixin's image config does not become the composed image's).filename: is workload-only; this kit
contributes a body through contentFile and the base decides which profile
file the agent reads.sbx@1. Both describe how the host drives the
workload's own entrypoint, which here is the base's.Pulls:
59
Last week