Paperclip as a mixin — Node 22, the pinned paperclipai CLI and its built UI in an overlay, with...
95
Paperclip as a mixin — Node 22, the pinned paperclipai CLI and its built UI in an overlay, with the Anthropic credential and the published web port. Layer it onto a shell base and run `paperclip`.
| Name | Required | Default | Description |
|---|---|---|---|
version | Optional | 2026.609.0 | paperclipai release to install |
[email protected]| Type | Required | Description | |
|---|---|---|---|
com.docker.sandbox/network-policy@1 | Required | — | |
com.docker.sandbox/credential@1 | Optional | Anthropic API access (API key or claude.ai subscription login) | |
com.docker.sandbox/port@1 | Required | — | |
com.docker.sandbox/lifecycle@1 | Required | — | |
com.docker.sandbox/agent-context@1 | Required | — | |
sbx run <agent> --kit docker/sbx-kit-paperclip-mixin:latestRun the following command to install sbx on your machine.
brew install docker/tap/sbxwinget install Docker.sbxNote
Experimental: Sandbox Kit v3This kit uses the experimental Sandbox Kit specification, specifically v3. The format and runtime behavior may change before v3 is stable.
Paperclip as a mixin — the same app as the
paperclip workload kit, packaged as an overlay you layer
onto a shell base instead of running as the sandbox's own image.
sbx run --kit ./paperclip-mixin/ <shell-workload>
Or from a git URL targeting this repo:
sbx run --kit "git+https://github.com/docker/sbx-kits-contrib.git#dir=paperclip-mixin" <shell-workload>
The base workload keeps its own launch command, so nothing starts the server for you:
paperclip # sources the resolved auth, then starts the server
sbx ports <sandbox> --publish 3100/tcp # reach the web UI
paperclip is the wrapper; paperclip-start beside it is the bare server
script it execs, and running that directly skips the Anthropic auth the
startup hook resolved.
npm/npx, which the server resolves agent CLIs through)
and the pinned paperclipai package with its built UI — all copied out of
a build stage on the same base the workload uses, because neither n nor
npm install -g takes a relocation flag.anthropic credential (API key or claude.ai
subscription login), the web port (3100), and the credential-resolution
startup hook.PAPERCLIP_*/HOST/SERVE_UI variables as a /etc/profile.d
snippet: a mixin's image config is not the composed image's, so ENV would
be dropped at assembly.Neither is copyable content, and neither is stated as a requires:
embedded-postgres binaries are linked for 4KB pages and fail on
the sandbox's 16KB-page arm64 kernel). An overlay can carry a binary tree
but not the shared libraries it links against or the dpkg state.
deb/postgresql would be the spec-sanctioned way to require it, but that
name is derived from the base's own package database and a base carrying a
versioned package instead would fail resolution while being perfectly
usable — so the dependency is documented rather than declared.
start-paperclip.sh fails loudly under set -e when it is missing.claude_local adapter shells out to it, and
the workload gets it from its claude-code template base.
requires: ["claude"] is the obvious statement and is deliberately not
made: the claude kit declares the same (anthropic, runtime) credential
this kit does, and one credential has one owner, so requiring it would make
the very composition it names illegal. Layer this onto a base image that
carries the CLI without declaring that credential itself.The standalone paperclip workload kit is the self-contained
alternative for both.
files/ and scripts/Both are byte-identical copies of ../paperclip/files/ and
../paperclip/scripts/. A kit's build context is its own directory, so an
overlay cannot reach its sibling workload's assets; diff -r between the
directories is what catches drift.
sbx@1. A mixin's image config never becomes the composed image's, so
there is no identity for the host to honor here.Pulls:
57
Last week