Pi as a mixin — the npm-installed coding agent and the `fd` binary its `find` tool probes for, ...
107
Pi as a mixin — the npm-installed coding agent and the `fd` binary its `find` tool probes for, in an overlay, with the Anthropic credential (API key or claude.ai OAuth). Layer it onto a shell base and run `pi`.
| Name | Required | Default | Description |
|---|---|---|---|
version | Optional | 0.86.1 | pi release to install |
[email protected]| Type | Required | Description | |
|---|---|---|---|
com.docker.sandbox/network-policy@1 | Required | — | |
com.docker.sandbox/credential@1 | Optional | Anthropic API access (API key or claude.ai OAuth) | |
com.docker.sandbox/lifecycle@1 | Required | — | |
com.docker.sandbox/agent-context@1 | Required | — | |
sbx run <agent> --kit docker/sbx-kit-pi-mixin:latestRun the following command to install sbx on your machine.
brew install docker/tap/sbxwinget install Docker.sbxNote
Experimental: Sandbox Kit v3This kit uses the experimental Sandbox Kit specification, specifically v3. The format and runtime behavior may change before v3 is stable.
pi as a
mixin — the same agent as the pi workload kit, packaged as an
overlay you layer onto a shell base instead of running as the sandbox's own
image.
sbx run --kit ./pi-mixin/ <shell-workload>
Or from a git URL targeting this repo:
sbx run --kit "git+https://github.com/docker/sbx-kits-contrib.git#dir=pi-mixin" <shell-workload>
The base workload keeps its own launch command, so nothing attaches the TUI for you:
pi
@earendil-works/pi-coding-agent package at the global
prefix it was built at, plus a /usr/local/bin/pi shim — copied out of a
build stage on the same base the workload uses, because npm install -g
takes no relocation flag.fdfind (Ubuntu's fd-find) and the fd symlink. pi's find tool probes
for it and would otherwise try to download a release binary from a host
this kit's allowlist does not name.anthropic credential (API key or claude.ai OAuth) and
the npm-proxy install hook.There is no /etc/profile.d snippet: the v2 kit declared no
environment.variables, so there is nothing for one to carry.
pi is an npm package and needs node >= 22.19.0 on PATH. The workload
installs none either — the shell templates already ship Node 22 — so this
overlay carries none, and pi works on a base that has one and fails on a base
that does not. v3 has no way to state that floor: requires: names kit
capabilities, and no base workload provides an entry for its language
runtimes. Use the pi workload kit if you need it self-contained.
filename: is workload-only; this kit
contributes a body through contentFile.sbx@1. Both describe how the host drives the
workload's own entrypoint, which here is the base's. The workload kit
declares prompt: ["-p", "{{.Prompt}}"]; from a shell you type the same
thing yourself.Pulls:
62
Last week