PicoClaw as a mixin — the pinned, SHA256-verified static binary in an overlay, with the Anthrop...
86
PicoClaw as a mixin — the pinned, SHA256-verified static binary in an overlay, with the Anthropic credential (API key or claude.ai OAuth), the published gateway and webhook ports, and the hooks that resolve the credential and bring the gateway up. Layer it onto a shell base and run `picoclaw`.
| Name | Required | Default | Description |
|---|---|---|---|
version | Optional | 0.2.9 | PicoClaw release to install |
[email protected]| Type | Required | Description | |
|---|---|---|---|
com.docker.sandbox/network-policy@1 | Required | — | |
com.docker.sandbox/port@1 | Required | — | |
com.docker.sandbox/port@1 | Required | — | |
com.docker.sandbox/credential@1 | Optional | Anthropic API access (API key or claude.ai OAuth) | |
com.docker.sandbox/lifecycle@1 | Required | — | |
com.docker.sandbox/agent-context@1 | Required | — | |
sbx run <agent> --kit docker/sbx-kit-picoclaw-mixin:latestRun the following command to install sbx on your machine.
brew install docker/tap/sbxwinget install Docker.sbxNote
Experimental: Sandbox Kit v3This kit uses the experimental Sandbox Kit specification, specifically v3. The format and runtime behavior may change before v3 is stable.
PicoClaw as a mixin — the same agent
as the picoclaw workload kit, packaged as an overlay you layer
onto a shell base instead of running as the sandbox's own image.
sbx run --kit ./picoclaw-mixin/ <shell-workload>
Or from a git URL targeting this repo:
sbx run --kit "git+https://github.com/docker/sbx-kits-contrib.git#dir=picoclaw-mixin" <shell-workload>
The base workload keeps its own launch command, so nothing attaches the agent CLI for you. The gateway still comes up with the container, so this works immediately:
picoclaw --help
picoclaw-start # resolves the credential, ensures the gateway, execs `picoclaw agent`
picoclaw release binary at
/usr/local/bin/picoclaw. One static Go binary with nothing to relocate,
which is why this overlay takes the plain FROM <base> AS build → /out →
FROM scratch shape rather than the copy-the-install-out shape the npm and
uv kits need.~/.picoclaw/config.json, the credential resolver, and
picoclaw-start on PATH.anthropic credential (API key or claude.ai OAuth), the
gateway (18790) and webhook (18791) ports, and both startup hooks.PICOCLAW_GATEWAY_HOST and PICOCLAW_HOME as a /etc/profile.d snippet:
a mixin's image config is not the composed image's, so ENV would be
dropped at assembly.files/files/ here is a byte-identical copy of ../picoclaw/files/. A kit's build
context is its own directory, so an overlay cannot reach its sibling
workload's assets; diff -r between the two directories is what catches
drift.
filename: is workload-only; this kit
contributes a body through contentFile.sbx@1. A mixin's image config never becomes the composed image's, so
there is no identity for the host to honor here.Pulls:
51
Last week