Skip to content

docs: add Docker Sandboxes (sbx) integration guide - #6331

Merged
lpcox merged 9 commits into
mainfrom
docs-sbx-integration
Jul 17, 2026
Merged

lpcox merged 9 commits into
mainfrom
docs-sbx-integration

Conversation

@lpcox

@lpcox lpcox commented Jul 17, 2026

Copy link
Copy Markdown
Collaborator

What

Adds docs/sbx-integration.md, a deep-dive on Docker Sandboxes (sbx) and how AWF uses it as an optional microVM backend for agent isolation.

Why

Two audiences:

  1. Engineers who want to understand how the existing --container-runtime sbx path works.
  2. Ourselves, if we later add another microVM backend running on top of KVM (Firecracker, Cloud Hypervisor, krun, etc.).

Contents

  • What sbx is — Docker's microVM product: per-sandbox kernel + Docker Engine (KVM on Linux), virtiofs workspace passthrough, host-side proxy for deny-by-default egress and credential injection, and the DOCKER_SANDBOXES_PROXY upstream-proxy hook. Sourced from the official Docker Sandboxes docs.
  • How AWF uses it — the executionModel (compose vs microvm) registry in src/container-runtime.ts; the sbx-manager.ts lifecycle wrapper; main-action.ts wiring (sbxStartContainers / sbxRunAgentCommand); egress chaining through AWF's Squid (gateway IP + published 3128); credential injection via the api-proxy over host.docker.internal; secret sanitization; and the strict-security handling for microVM runtimes.
  • Adding a KVM-based backend — a concrete checklist covering the registry entry, manager implementation, the critical egress-chaining seam, main-action.ts wiring, and lessons learned (daemon/proxy ordering, cross-boundary health gating, env-leakage separation, DNS, exit-code fidelity).
  • A traffic-flow mermaid diagram and a responsibility-split table (what sbx owns vs. what AWF owns).

Notes

  • Docs-only change. markdownlint-cli2 passes on the new file; cross-links use the relative ./file.md style consistent with the rest of docs/.
  • Complements the existing docs/sandbox-design.md (which explains why the default backend is Docker + Squid rather than a microVM).

Explain what Docker Sandboxes (sbx) is and how AWF uses it as a microVM
backend: the executionModel abstraction, sbx-manager lifecycle wrapper,
main-action wiring, egress chaining through AWF's Squid, credential
injection via the api-proxy, and secret sanitization. Includes a guide
for adding another KVM-based microVM backend.

Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Copilot-Session: 23717692-af7a-4e03-a156-5b696c3f01bd
Copilot AI review requested due to automatic review settings July 17, 2026 18:26
@github-actions

github-actions Bot commented Jul 17, 2026 •

Copy link
Copy Markdown
Contributor

Documentation Preview

Documentation build failed for this PR. View logs.

Built from commit b213ef3

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Adds a guide for AWF’s optional Docker Sandboxes microVM backend and future backend development.

Changes:

  • Documents sbx architecture and AWF lifecycle integration.
  • Describes networking, credential isolation, and traffic flow.
  • Provides a checklist for adding KVM-based backends.
Show a summary per file
File Description
docs/sbx-integration.md Adds the sbx integration and extension guide.

Review details

Tip

Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

  • Files reviewed: 1/1 changed files
  • Comments generated: 8
  • Review effort level: Medium

Comment thread docs/sbx-integration.md Outdated
Comment thread docs/sbx-integration.md Outdated
Comment thread docs/sbx-integration.md Outdated
Comment on lines +175 to +179
- **Squid** is reached at the **sbx gateway IP** (`172.17.0.0` in code, i.e. the
docker0 bridge range) on its published port `3128`, rather than the internal
`172.30.0.10`. AWF sets `DOCKER_SANDBOXES_PROXY = http://<squidIp>:3128` so the
sandbox's own proxy chains upstream into AWF's Squid, where the domain ACL is
enforced.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Fixed in docs: correct DOCKER_SANDBOXES_PROXY claim in sbx-integration.md. The networking section now accurately documents that:

  • AWF sets HTTP_PROXY/HTTPS_PROXY inside the sandbox (not DOCKER_SANDBOXES_PROXY)
  • DOCKER_SANDBOXES_PROXY is explicitly noted as not set by AWF, with the reason (it's a daemon-start setting AWF doesn't control)
  • The "net effect" clarifies only proxy-aware tools are covered by AWF's Squid ACL

The mermaid diagram was also updated to show the actual traffic flow: proxy-aware tools → Squid; proxy-unaware tools → sbxproxy (not filtered by AWF ACL).

Comment thread docs/sbx-integration.md
Comment thread docs/sbx-integration.md Outdated
Comment thread docs/sbx-integration.md Outdated
Comment thread docs/sbx-integration.md Outdated
Comment thread docs/sbx-integration.md Outdated
lpcox and others added 2 commits July 17, 2026 11:37
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
@github-actions

github-actions Bot commented Jul 17, 2026 •

Copy link
Copy Markdown
Contributor

✅ Copilot review passed with no inline comments.

@lpcox Add the ready-for-aw label to this PR to trigger agentic CI smoke tests.

lpcox and others added 5 commits July 17, 2026 11:37
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
Copilot finished work on behalf of lpcox July 17, 2026 18:47
@lpcox
lpcox merged commit 3acca5e into main Jul 17, 2026
17 checks passed
@lpcox
lpcox deleted the docs-sbx-integration branch July 17, 2026 19:55
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants