Skip to content

v0.38.0-rc3

Pre-release
Pre-release

Choose a tag to compare

@docker-read-write docker-read-write released this 04 Aug 09:37
e4809b1

Highlights

Kit spec v2. A new schema is available for authoring kits, with a clearer structure for setup, permissions, agent instructions, networking, and credentials. Use schemaVersion: "2" for new kits; existing v1 kits continue to load through the legacy path. See the kit spec reference for migration details.

Local models (experimental). sbx run --model <name> claude serves a local GGUF model via llmman — or an already-running Ollama install with an ollama/ prefix — and routes Claude Code at it instead of api.anthropic.com. Enable with sbx settings set platform.allowExperimentalFeatures true and sbx settings set feature.model true.

MCP management is now a first-class feature. Use sbx mcp --help to learn more.

Enterprise networking. Settings-driven upstream-proxy configuration with separate sandbox and daemon scopes, integrated NTLM/Kerberos proxy authentication on Windows, and a new --deny-network flag for per-sandbox egress rules at creation time.

What's New

CLI

  • sbx create and sbx run show detailed structured progress during startup, including environment files loaded, resources provisioned, and each kit command's outcome; kit-install progress streams live during sbx create --kit.
  • Added sbx daemon restart to stop and restart the sandboxd daemon in the background.
  • sbx inspect now displays custom secrets configured for a sandbox.
  • sbx run --gpu (experimental) opts a sandbox into NVIDIA VFIO GPU passthrough on Linux. (enable via sbx settings set feature.sandbox-gpu true
  • DOCKER_SANDBOXES_CLONED_WORKSPACE_SIZE configures the size of the cloned workspace volume.
  • sbx setup ssh warns when ssh is missing from PATH, and on Windows when sh (required by Claude Desktop's SSH ProxyCommand) is missing.
  • Port publishing failures now identify the affected host port and explain when the OS requires extra daemon privileges.

MCP

  • The sbx mcp subcommand is now available for managing MCP servers.
  • Includes dynamic MCP tools (mcp-find, mcp-add, mcp-config-set) for attaching registered servers to sandboxes.
  • Govern MCP servers and tools for organization using Cedar policies.

Networking & Policy

  • Settings-driven upstream-proxy configuration with separate sandbox and daemon scopes (proxy, proxy.sandbox, proxy.daemon, and matching no_proxy settings), defaulting to the host OS system proxy; the daemon's own traffic (image pulls, telemetry) is proxied too.
  • sbx can authenticate to upstream proxies requiring integrated NTLM or Kerberos/Negotiate authentication on Windows via the opt-in proxy.integratedAuth setting.
  • --deny-network HOST on sbx run and sbx create records per-sandbox network deny rules at creation time, with layer-aware egress messages.
  • Added tls.allowNegativeSerial for TLS-inspecting proxies that issue certificates with negative serial numbers.
  • sbx policy allow network reports a clear "managed by your organization" error when org governance overrides the local allow, and failed rule removals now explain what went wrong using a single rule identifier.
  • Signing in refreshes organization policies in the running daemon immediately instead of waiting for the next polling interval.
  • IP-literal destinations denied by a CIDR rule fail fast with a policy message instead of timing out.
  • Blocked HTTPS proxy connections appear in sbx policy log even when the client aborts the TLS handshake.

Secrets & Credentials

  • Service and custom secrets are global by default, with --sandbox for sandbox scope; legacy positional and --global forms are deprecated with warnings.
  • Sandbox-scoped GitHub credentials added after creation now work without recreating the sandbox.
  • Pressing Ctrl+C while entering a secret cancels the command without saving it.

Agents

  • Docker Agent and OpenCode sandboxes can authenticate GitHub Copilot requests with proxy-managed GitHub credentials.
  • Codex sandboxes created from the TUI prefer stored OpenAI OAuth credentials over API keys; kit environment variables now reach cloud agents, and git no longer hangs Codex startup prompting for credentials.
  • Shared agent skills: directory symlinks under the skills folder are resolved and their contents imported.

Kits & Templates

  • Kit specs use the new v2 grammar.
  • Kits using extends correctly inherit and override the base image or build source of their parent.
  • Kit install commands can consume static files from files/home, including binary files.

Packaging

  • Homebrew installs from a stapled .dmg artifact rather than a .tar.gz archive, improving Gatekeeper compatibility on macOS.
  • Windows: the running sandboxd daemon is stopped during a WinGet/MSI upgrade so client and server end up on the same version.

Security

  • Claude Desktop SSH sessions no longer expose Desktop OAuth access tokens inside sandboxes.
  • Fixed a destination-escape flaw in sbx cp copy-out (CVE-2026-17106).
  • The daemon's loopback egress proxy only serves the daemon's own traffic, preventing other local users on a multi-user host from reaching the configured upstream proxy through it.

Bug Fixes

  • Fixed a hang where sandboxd stopped answering all endpoints and could not be stopped without SIGKILL after a crash; fatal daemon tracebacks are now included in sbx diagnose --upload bundles.
  • Fixed sbx daemon stop hanging when an idle SSH session (e.g. Claude Desktop) was connected to a sandbox.
  • sandboxd automatically repairs a corrupted local image cache by re-pulling the image, and otherwise reports a clear "run sbx daemon reset" error.
  • Fixed recreate failures ("base image not found") after daemon restarts when swapping a sandbox's container via sbx kit add; recreates self-heal by recomposing from the sandbox's template.
  • Fixed reverse DNS (PTR) lookups from sandboxes returning NXDOMAIN for container-resolved addresses.
  • Fixed a goroutine and network-endpoint leak from hijacked HTTP CONNECT tunnels that could eventually stall sandbox creation after many delete/recreate cycles.
  • Fixed an intermittent 500 error when deleting a sandbox while its network endpoints were being torn down.
  • The daemon restores saved sandboxes' network proxies in parallel on restart, speeding up startup with several sandboxes and fixing a potential crash during first-run policy application.
  • Fixed host .git/config corruption when creating a sandbox for repositories using includeIf directives in ~/.gitconfig; the sandbox now writes git identity only to the container's gitconfig.
  • sbx skills shows a single usage form and clearer help for importing shared agent skills.
  • sbx no longer reports that a stored credential was not injected when the daemon injects it.