NanoClaw as a mixin -- the host process and its checkout in an overlay, with the Docker Hub, OneC...
92
NanoClaw as a mixin -- the host process and its checkout in an overlay, with the Docker Hub, OneCLI, Claude and chat-channel egress and the published webhook and OneCLI ports. Layer it onto a base that already carries a Node runtime and run `nanoclaw-start`.
nanoclaw| Type | Required | Description | |
|---|---|---|---|
com.docker.sandbox/network-policy@1 | Required | — | |
com.docker.sandbox/port@1 | Required | — | |
com.docker.sandbox/port@1 | Required | — | |
com.docker.sandbox/port@1 | Required | — | |
com.docker.sandbox/agent-context@1 | Required | — | |
deb/docker-cesbx run <agent> --kit docker/sbx-kit-nanoclaw-mixin:latestRun the following command to install sbx on your machine.
brew install docker/tap/sbxwinget install Docker.sbxNote
Experimental: Sandbox Kit v3This kit uses the experimental Sandbox Kit specification, specifically v3. The format and runtime behavior may change before v3 is stable.
NanoClaw as a mixin — the same
agent as the nanoclaw workload kit, packaged as an overlay you
layer onto an existing base instead of running as the sandbox's own image.
Read this first. NanoClaw is distributed as a prebuilt third-party image, not as an install this repo drives. An overlay is a delta, so this mixin carries the NanoClaw host launcher and its checkout — and not the Node runtime, OneCLI and Postgres clients, and system packages that image installs around them. Compose it only onto a base that already carries an equivalent runtime. If you want a sandbox that just works, use the workload kit.
sbx run --kit ./nanoclaw-mixin/ <base-workload>
Or from a git URL targeting this repository:
sbx run --kit "git+https://github.com/docker/sbx-kits-contrib.git#dir=nanoclaw-mixin" <base-workload>
The base workload keeps its own launch command, so nothing starts NanoClaw for you:
/usr/local/bin/nanoclaw-start
/usr/local/bin/nanoclaw-start and /home/agent/nanoclaw, copied out of the
published NanoClaw image.profile.d export — a mixin's image
config does not become the composed image's.requires: names kit capabilities and no base
workload provides one for its interpreter.filename: is workload-only; this kit
contributes a body through contentFile.Pulls:
56
Last week