# YOLO Mode, Safely: MicroVM Sandboxes for Any Agent — Rowan Christmas, Docker

## Executive summary

The talk addresses the critical security vulnerability posed by coding agents, which can access sensitive Personally Identifiable Information (PII) and internal data even when running within seemingly safe coding harnesses. The solution presented is Docker Sandboxes (sbx), which utilize microVM technology to provide 'security by design.' By running agents within an isolated virtual machine with its own kernel, sbx enforces strict controls, including default-deny networking, filesystem isolation, and secret placeholders, ensuring that agents cannot access host secrets or perform unauthorized actions.

## Key takeaways

- Coding Agents Pose Significant Security Risks: Agents can find and surface sensitive data (e.g., browser history, bank account details) from the host machine, even if the user assumes the coding environment is safe. This risk is not limited to malicious intent, as agents can be prompted to research security topics and reveal PII.
- MicroVMs Offer Superior Security Isolation: Unlike traditional harness-level guardrails, microVMs provide true isolation by running their own kernel and isolating the filesystem. This prevents agents from accessing host secrets or performing unauthorized network requests.
- sbx Provides Comprehensive Governance Controls: Docker Sandboxes (sbx) offer granular governance, including network allow/deny rules, filesystem rules, and the ability to track agent identity and delegation chains. This allows organizations to enforce policy-based governance.

## Technical details

- Docker Sandboxes (sbx) Architecture: sbx is a microVM that spins up an isolated VM with its own kernel, filesystem isolation, and secret placeholders. It is designed to be secure by design, not just by policy warnings.
- Network and Data Leakage Prevention: The sandbox enforces default-deny networking and blocks unauthorized network egress (e.g., attempts to look up content on the Pirate Bay) and prevents agents from sending excessive telemetry data to external services.
- Advanced Governance Features: Future and current controls include agent-level identity tracking, delegation chains, policy enforcement based on Cedar policies, L7 networking controls, and per-GitHub repository file system controls (allowing read/write access only to specified areas).
- Usage and Compatibility: The sandbox is easy to use via the `sbx run` command and is compatible with various agents, including Claude Code and Codex. It can run a full VM environment, allowing for shell access, Python jobs, or web servers.

## Practical implications

- When integrating AI agents into build or development workflows, always run them within a microVM sandbox (sbx) to prevent data leakage and unauthorized access to host resources.
- Use the sandbox's read-only mount feature when working with related codebases to ensure agents only interact with the specific repositories required for the task.
- Implement policy-based governance (e.g., Cedar policies) to define explicit boundaries for agent actions, moving beyond simple 'please don't do this' warnings.

## Topics

AI Governance, MicroVMs, Security Engineering, Agentic Workflows, CI/CD Security, Docker Sandboxes (sbx), Docker Docs for AI Sandboxes, sbx releases (GitHub)

Source: https://www.youtube.com/watch?v=OE_lLNCNfQo
