Repository navigation
Add Docker Sandboxes integration guide - #638
Conversation
Document running Kernel inside Docker Sandboxes with the Kernel kit (docker.io/sbx/kernel-kit): storing the API key, launching an agent with --kit, approving the credential request, verifying the setup, how the host proxy keeps the key out of the sandbox, the kit's network rules, v2 kit compatibility, troubleshooting, and cleanup. Add the black Docker mark from Docker's official logo kit as the page icon, and list the page in the Integrations nav and overview. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
|
Preview deployment for your docs. Learn more about Mintlify Previews.
💡 Tip: Enable Automations to automatically generate PRs for you. |
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
There was a problem hiding this comment.
Risk level: Very Low. Approving.
The diff is documentation for the Mintlify site only:
integrations/docker-sandboxes.mdx— new integration guide (user-facing docs, not a model instruction file)integrations/overview.mdx— one overview linkdocs.json— one Integrations nav entryimages/integration-icons/docker.svg— static Docker mark (paths and fills only; no scripts or external references)
No application logic, auth, permissions, infrastructure, or shared runtime code is changed. Blast radius is the docs site navigation and one new page. No CODEOWNERS file is present, and this PR has no existing approval.
Sent by Cursor Automation: Assign PR reviewers
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
There was a problem hiding this comment.
Risk level: Very Low. Existing approval stands.
Re-checked after 78a5b248 (“Narrow the CLI install troubleshooting hint to release downloads”). The only change since the prior approval is one sentence in integrations/docker-sandboxes.mdx: “blocked npm or GitHub requests” became “blocked npm or GitHub release downloads.” Risk did not increase, so this approval is not dismissed and is not repeated.
Full diff remains documentation for the Mintlify site:
integrations/docker-sandboxes.mdx— new user-facing integration guide (not a model instruction file)integrations/overview.mdx— one overview linkdocs.json— one Integrations nav entryimages/integration-icons/docker.svg— static Docker mark (paths and fills only)
No application logic, auth, permissions, infrastructure, or shared runtime code changed. No CODEOWNERS file is present. Blast radius is the docs site navigation and one new page.
Sent by Cursor Automation: Assign PR reviewers
rgarcia
left a comment
There was a problem hiding this comment.
reviewed — looks good, approving. a couple of things worth fixing before merge, mainly the stale network rules:
Bugs
integrations/docker-sandboxes.mdx:196— network table is stale: the current kit (docker/sbx-kits-contrib#335, 2026-09-28) allows**.onkernel.comand*.kernel.sh("Direct CDP endpoints are served from hosts under kernel.sh").sbx kit inspect docker.io/sbx/kernel-kit:latestshows 9 allow rules. consider adding a*.kernel.shrow — this also answers the open*.kernel.shquestion in the PR description. same applies to:107and:217, which only mention*.onkernel.comintegrations/docker-sandboxes.mdx:211— the pinned-tag example20260924-d058…predates that fix (8 allow rules, no*.kernel.sh), so anyone pinning it gets the old kit. consider20260928-7da9425e640d172e36abe6de3499a1c75d416c0f, whichlatestcurrently points tointegrations/docker-sandboxes.mdx:105— "it never has your key, so it can't leak it" overclaims a bit: the agent can't read the key, but anything in the sandbox can still make authenticated Kernel API calls through the proxy while it runs. maybe "your agent can't read or exfiltrate the key, though anything in the sandbox can make authenticated Kernel API calls while it runs"
Questions
integrations/docker-sandboxes.mdx:63-70— checks 1–2 wrap insh -lcbut check 3 callskerneldirectly. if the login shell is needed for PATH/env, check 3 can fail for the wrong reason; if not, consider dropping it from check 1 (check 2 still needssh -cfor the$KERNEL_API_KEYexpansion)integrations/docker-sandboxes.mdx:73— is the placeholder literallyproxy-managed? worth confirming in the e2e pass, or soften to "prints a placeholder"
Nits
integrations/docker-sandboxes.mdx:15-17— the upstream kit README says it works with any agent that ships npm, which might be worth saying here. "This guide covers local sandboxes." reads a little cut off — maybe say cloud sandboxes are untested, or drop itintegrations/docker-sandboxes.mdx:29— on headless Linux with no Secret Service,sbxfalls back to a 0700 file under~/.config/com.docker.sandboxes; maybe "usually your OS keychain"
The published kit now allows **.onkernel.com and *.kernel.sh so browser connections work under restrictive network policies. Update the network table, the key-isolation section, troubleshooting, and the pinned tag to match. Also run the verification checks without a login shell, note that anything in the sandbox can make authenticated API calls, and say the kit works with any agent whose sandbox has npm. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
|
Thanks Raf, addressed in 9ed63f8. Bugs
Questions
Nits
Still open for the e2e pass: a real CDP connect under Balanced or Locked Down. docs.docker.com still lists |
…oxes-docs # Conflicts: # docs.json


Description
Adds an integration guide for running Kernel inside Docker Sandboxes with the Kernel kit (
docker.io/sbx/kernel-kit).integrations/docker-sandboxes.mdxcovers:sbx secret set kernel--kitand approving the credential requestimages/integration-icons/docker.svgis the black Docker mark from Docker's official logo kit, unmodified. The sidebar's dark-modeinvert(1)rule renders it white, which is also an approved Docker logo color.docs.json) and inintegrations/overview.mdx.Implementation Checklist
Testing
mint devrenders the page, and the sidebar icon shows correctly in light and dark modemint broken-linkspassesdocker.io/sbx/kernel-kit:latestand20260928-7da9425e640d172e36abe6de3499a1c75d416c0fhave the same digest, and the kit's spec allows**.onkernel.comand*.kernel.shfor browser connections.sbx secret set kernel, thensbx run claude --name kernel-demo --kit docker.io/sbx/kernel-kit:latest, the approval prompt, and a browser tasksbx execchecks under "Verify the setup", which run without a login shell. The second printsproxy-managed, the placeholder Docker's kit-author guide documents for proxy-managed credentials.connectOverCDP) under the Balanced or Locked Down network policy, which exercises the**.onkernel.comand*.kernel.shrules. docs.docker.com still lists multi-label**.wildcards in kits as "parsed; enforcement pending", while Docker's kit-author guide says they're enforced.sbx skills add kernel/skills --skill kernel-climakes the skill available in new sandboxes. The command is experimental; cut that section if it doesn't work.Visual Proof
Checked locally with
mint devin light and dark mode. Screenshots aren't attached.Additional Notes
docker/sbx-kits-contrib/kernel, which the page links as the kit's source.🤖 Generated with Claude Code
Note
Low Risk
Documentation and navigation only; no product code, APIs, or runtime behavior changes.
Overview
Adds documentation for using Kernel cloud browsers inside Docker Sandboxes via the
docker.io/sbx/kernel-kitkit.The new
integrations/docker-sandboxespage walks throughsbx secret set kernel, launching an agent with--kit, credential approval, verification commands, what the kit installs, host-side API key proxying (including CI pre-approval), optional SDK setup, network policy rules, kit versioning, troubleshooting, and cleanup. A Docker sidebar icon (images/integration-icons/docker.svg) is included, and the page is linked fromdocs.jsonIntegrations nav andintegrations/overview.mdx.Reviewed by Cursor Bugbot for commit de7862a. Bugbot is set up for automated code reviews on this repo. Configure here.