Skip to content

feat(docker-sandbox-kit): bind a Sandbox Kit v3 descriptor as a declared TRACE policy - #249

Merged
imran-siddique merged 1 commit into
mainfrom
feat/docker-sandbox-kit
Oct 1, 2026
Merged

imran-siddique merged 1 commit into
mainfrom
feat/docker-sandbox-kit

Conversation

@imran-siddique

Copy link
Copy Markdown
Member

Adds integrations/docker-sandbox-kit, a Level 0 record producer for Docker Sandbox Kit v3, the Apache-2.0 spec Docker is taking to the CNCF.

A Kit is one OCI image whose vnd.docker.sandbox.kit.descriptor annotation lists what the agent inside it asks to reach: network allow and deny by phase, credentials, volumes, ports. SPEC-v3 section 9.1 makes the published descriptor what signatures cover and what the gate judges, so it is a real policy artifact. The adapter binds its exact bytes into policy.bundle_hash, puts the Kit manifest digest in origin.source_event_id and policy.policy_uri, and takes the digest of the image that ran from the caller.

enforcement_mode is always declared, with no argument to change it. The granted permission surface lives in the runtime's lock (SPEC-v3 sections 7.4 and 10), not in the image, so a record built from the image can name the requested policy and nothing more. The Kit digest is not used as build_provenance.digest either, because SPEC-v3 section 10 says the assembled image, not the published Kit, is what runs.

Verification, all against released packages (agentrust-trace 0.11.0, agentrust-trace-adapters 0.1.1, agentrust-trace-tests 0.6.1):

  • Fixtures are the registry bytes of docker/sbx-kit-claude-acp-set 1.0.1 (sha256:86d56a3b..., seven capability types including network-policy@1 and credential@1) and docker/doodle 2026 (sha256:c9bce67a...), pulled 2026-10-01.
  • 19 tests: both Kits build, schema-check, sign and verify, and nine refusal paths (index, artifact manifest, not a Kit, v2 grammar, set, YAML descriptor, schema-version mismatch, capability index mismatch, re-serialised bytes) exit without a record.
  • A signed record from either Kit passes trace-tests verify --level 0, 15 checks, 4 skipped.
  • The README fetch and CLI steps were run end to end against Docker Hub.

agentrust-trace-adapters 0.1.1 predates declared (#223 is merged but unreleased), so the adapter passes build_record a two-member policy object of its own until the next release. marketplace/catalog.json and the README index are regenerated by the existing scripts, and validate_integrations.py reports 42 integrations with 0 failures.

🤖 Generated with Claude Code

…red TRACE policy

Reads a Kit's platform manifest, hashes the published
vnd.docker.sandbox.kit.descriptor annotation into policy.bundle_hash and
records enforcement_mode declared, since the granted surface lives in the
runtime lock rather than the image (SPEC-v3 sections 7.4 and 10). The Kit
digest goes to origin.source_event_id and policy.policy_uri; the caller
supplies the digest of the assembled image that ran.

Fixtures are registry bytes of docker/sbx-kit-claude-acp-set 1.0.1 and
docker/doodle 2026. 19 tests on agentrust-trace 0.11.0 and
agentrust-trace-adapters 0.1.1; signed records pass trace-tests 0.6.1 at
Level 0.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@imran-siddique
imran-siddique requested review from a team and carloshvp as code owners October 1, 2026 22:09
@imran-siddique
imran-siddique merged commit 9e601e2 into main Oct 1, 2026
25 checks passed
@imran-siddique
imran-siddique deleted the feat/docker-sandbox-kit branch October 1, 2026 22:23
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants