Sign inSign up

docker/sbx-kit-pi-mixin

Verified Publisher

By Docker, Inc.

•Updated 8 days ago

Pi as a mixin — the npm-installed coding agent and the `fd` binary its `find` tool probes for, ...

Sandbox Kit
0

107

docker/sbx-kit-pi-mixin repository overview

Digest

sha256:a47003e1006c…

Size

25.9 MB

Schema

v3

Pushed

8 days ago

Specificationspec.yaml

MIXIN

Pi as a mixin — the npm-installed coding agent and the `fd` binary its `find` tool probes for, in an overlay, with the Anthropic credential (API key or claude.ai OAuth). Layer it onto a shell base and run `pi`.


Arguments
NameRequiredDefaultDescription
versionOptional0.86.1

pi release to install



CapabilitiesExpand a row to see its full configuration. See the full spec for the complete descriptor.
TypeRequiredDescription
com.docker.sandbox/network-policy@1Required—
com.docker.sandbox/credential@1OptionalAnthropic API access (API key or claude.ai OAuth)
com.docker.sandbox/lifecycle@1Required—
com.docker.sandbox/agent-context@1Required—

Apply this mixin to a sandbox

sbx run <agent> --kit docker/sbx-kit-pi-mixin:latest

Make sure you have docker sbx installed

Run the following command to install sbx on your machine.

macOS
brew install docker/tap/sbx
Windows
winget install Docker.sbx
Learn more about docker sbx⁠

Note

Experimental: Sandbox Kit v3

This kit uses the experimental Sandbox Kit specification⁠, specifically v3⁠. The format and runtime behavior may change before v3 is stable.

⁠pi-mixin

pi⁠ as a mixin — the same agent as the pi⁠ workload kit, packaged as an overlay you layer onto a shell base instead of running as the sandbox's own image.

⁠Usage

sbx run --kit ./pi-mixin/ <shell-workload>

Or from a git URL targeting this repo:

sbx run --kit "git+https://github.com/docker/sbx-kits-contrib.git#dir=pi-mixin" <shell-workload>

The base workload keeps its own launch command, so nothing attaches the TUI for you:

pi

⁠What it carries

  • The npm-installed @earendil-works/pi-coding-agent package at the global prefix it was built at, plus a /usr/local/bin/pi shim — copied out of a build stage on the same base the workload uses, because npm install -g takes no relocation flag.
  • fdfind (Ubuntu's fd-find) and the fd symlink. pi's find tool probes for it and would otherwise try to download a release binary from a host this kit's allowlist does not name.
  • The proxy-managed anthropic credential (API key or claude.ai OAuth) and the npm-proxy install hook.

There is no /etc/profile.d snippet: the v2 kit declared no environment.variables, so there is nothing for one to carry.

⁠Known limitation: the Node runtime

pi is an npm package and needs node >= 22.19.0 on PATH. The workload installs none either — the shell templates already ship Node 22 — so this overlay carries none, and pi works on a base that has one and fails on a base that does not. v3 has no way to state that floor: requires: names kit capabilities, and no base workload provides an entry for its language runtimes. Use the pi⁠ workload kit if you need it self-contained.

⁠What it deliberately leaves to the base workload

  • The launch command. A mixin does not set an entrypoint.
  • The context-file profile. filename: is workload-only; this kit contributes a body through contentFile.
  • Session verbs and sbx@1. Both describe how the host drives the workload's own entrypoint, which here is the base's. The workload kit declares prompt: ["-p", "{{.Prompt}}"]; from a shell you type the same thing yourself.

This week's pulls

Pulls:

62

Last week