feat(docker-sandbox-kit): bind a Sandbox Kit v3 descriptor as a declared TRACE policy - #249
Merged
Merged
Conversation
…red TRACE policy Reads a Kit's platform manifest, hashes the published vnd.docker.sandbox.kit.descriptor annotation into policy.bundle_hash and records enforcement_mode declared, since the granted surface lives in the runtime lock rather than the image (SPEC-v3 sections 7.4 and 10). The Kit digest goes to origin.source_event_id and policy.policy_uri; the caller supplies the digest of the assembled image that ran. Fixtures are registry bytes of docker/sbx-kit-claude-acp-set 1.0.1 and docker/doodle 2026. 19 tests on agentrust-trace 0.11.0 and agentrust-trace-adapters 0.1.1; signed records pass trace-tests 0.6.1 at Level 0. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
satishaakula
approved these changes
Oct 1, 2026
This was referenced Oct 1, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Adds
integrations/docker-sandbox-kit, a Level 0 record producer for Docker Sandbox Kit v3, the Apache-2.0 spec Docker is taking to the CNCF.A Kit is one OCI image whose
vnd.docker.sandbox.kit.descriptorannotation lists what the agent inside it asks to reach: network allow and deny by phase, credentials, volumes, ports. SPEC-v3 section 9.1 makes the published descriptor what signatures cover and what the gate judges, so it is a real policy artifact. The adapter binds its exact bytes intopolicy.bundle_hash, puts the Kit manifest digest inorigin.source_event_idandpolicy.policy_uri, and takes the digest of the image that ran from the caller.enforcement_modeis alwaysdeclared, with no argument to change it. The granted permission surface lives in the runtime's lock (SPEC-v3 sections 7.4 and 10), not in the image, so a record built from the image can name the requested policy and nothing more. The Kit digest is not used asbuild_provenance.digesteither, because SPEC-v3 section 10 says the assembled image, not the published Kit, is what runs.Verification, all against released packages (
agentrust-trace0.11.0,agentrust-trace-adapters0.1.1,agentrust-trace-tests0.6.1):docker/sbx-kit-claude-acp-set1.0.1 (sha256:86d56a3b..., seven capability types includingnetwork-policy@1andcredential@1) anddocker/doodle2026 (sha256:c9bce67a...), pulled 2026-10-01.set, YAML descriptor, schema-version mismatch, capability index mismatch, re-serialised bytes) exit without a record.trace-tests verify --level 0, 15 checks, 4 skipped.agentrust-trace-adapters0.1.1 predatesdeclared(#223 is merged but unreleased), so the adapter passesbuild_recorda two-member policy object of its own until the next release.marketplace/catalog.jsonand the README index are regenerated by the existing scripts, andvalidate_integrations.pyreports 42 integrations with 0 failures.🤖 Generated with Claude Code