What's new
Breaking changes
- Secret commands configured with
sbx secret set --command,sbx secret set-custom --command, orsecrets.<name>.commandin an environment file execute from a fresh temporary directory on the host. Relative paths such as./credential-helperno longer resolve from the project directory or the directory where you ransbx. Store helpers and their dependencies outside writable sandbox mounts. Run helpers by name from an absolute directory on the host'sPATH, use absolute paths, or explicitly change to their private directory in the command. For existing environments that declare secret commands, the nextsbx env runasks you to approve a one-time plan change for the working directory. The execution change takes effect after upgrading and restarting the daemon, even before you approve that plan.
Cloud sandboxes
sbx --cloud create --on-timeout restartacceptsrestartas the timeout action. When the sandbox reaches its time limit, it stops and immediately restarts instead of remaining stopped.sbx --cloud createpasses--kit-argand--kit-args-filevalues to kits supplied with--kit.
Kits and skills
- Kits can install files in the agent's skills directory when shared skills are read-only. The shared skills store remains read-only, while kit installation and startup commands can write their own skills without a read-only filesystem error.
- Kits added through the runtime API retain their network rules and applicable agent instructions when another kit addition recreates the sandbox container.
sbx kit addwarns if it cannot save the updated sandbox record. The warning explains which kit settings could be lost and whether a daemon restart or another container replacement would cause the loss.
Agents and models
- The local model server starts and stops with the Docker Sandboxes daemon and downloads its llama.cpp runtime when the daemon starts. The macOS and Windows bundles include llmman v0.1.418, which manages the runtime download instead of relying on a separately bundled
llama-server. - Image paste in WSL2 falls back to the Windows clipboard when Linux clipboard tools return no image. Requires
clipboard.imagePasteto be enabled.
Sandbox lifecycle and workspaces
- Fixed a shutdown bug affecting templates that use dash as
/bin/sh, including the built-in Ubuntu-based templates. The shutdown handler forwardsSIGTERMcorrectly, giving sandbox processes a chance to exit gracefully instead of waiting five seconds for a forced shutdown. - On Linux arm64 hosts, the default CPU allocation is capped at 16 CPUs per sandbox. This fixes startup failures with
VM did not connect within 15swhen several sandboxes start together on hosts with many CPU cores. Use--cpusto request a larger allocation. sbx umountcan remove a saved mount from a stopped sandbox using the original host path even after that directory has been deleted.- On macOS, mounting, unmounting, and restoring saved mounts consistently recognize host paths whose capitalization differs.
- If the runtime fails to mount the workspace, sandbox startup reports the mount failure and points to the daemon log for the cause instead of reporting a generic container startup error.
- Starting a second daemon against a state directory already in use fails with an error instead of disrupting the running daemon.
sbx resetstops background feature-flag updates and log writes before deleting local state, preventing leftover files and recreated directories. On Windows, it also closes daemon log files before deleting them to avoid cleanup retries caused by open file handles.
Authentication and credentials
- Removing secrets in bulk revokes credentials from running sandboxes. Failed revocations can be retried even after the stored secrets have been deleted.
Networking and policy
- Sandboxes created with the
balancednetwork policy preset can download Playwright browser binaries fromcdn.playwright.devover HTTPS. Existing sandboxes keep their saved policies. To use the updated preset, create a new sandbox with thebalancednetwork policy.
CLI and diagnostics
sbx envreports unrecognized environment-file keys with the file, line, and column where they were declared, including when multiple files are merged.- Canceling a batch
sbx rmorsbx stopstops processing the remaining sandboxes instead of printing a cancellation error for each one. sbx diagnose --uploadreturns a non-zero exit status if the requested diagnostics upload fails, so scripts can detect the failure.sbx diagnosereports the socket-path length limit used by the container runtime asruntime_socket_limit_bytesand clarifies the meaning of the reported socket-path values.
Packaging and installation
- Windows MSI installations include
llmmanand the guest kernel, fixing local model serving withsbx run --modeland sandbox launches that failed withNo kernel specified. - Uninstalling Docker Sandboxes through the Windows MSI stops the daemon.
- Fixed the Linux static tarball failing to start on distributions with older glibc versions. The tarball is built against glibc 2.34.