Docker Skills, Part 4: Sandbox Lifecycle, Network Policy, and Credentials
One command, sbx run claude ., and Claude gets a complete, disposable place to work: its own filesystem, its own network, its own Docker daemon, built from the current directory in a few seconds, instead of running directly on your machine with your own shell, your own files, and your own network access. That’s Docker Sandboxes: a standalone sbx CLI that runs an AI coding agent inside an isolated microVM so a runaway command, a bad rm, or a prompt-injected instruction stays contained to a disposable environment instead of your actual laptop. See the Docker Sandboxes documentation for the full product picture; docker-sandboxes-lifecycle and docker-sandboxes-network-credentials, the two skills this post covers, are what make that sandbox practical to drive day to day: how isolated the agent’s workspace is, how you get back into a sandbox you left running, and exactly what it can reach on the network and authenticate with. ...