Skip to content
TECH CEO Daily
SaaSLaunch

Docker Cloud Sandboxes launch for AI coding agents, priced from $0.07 an hour

Docker now runs AI coding agents in isolated cloud microVMs billed by the second, and is taking its agent permission format to the Cloud Native Computing Foundation.

By · Editor

· 3 min read · Fact-checked

The 60-second brief

  • 1Docker Cloud Sandboxes launched on September 24, billed per second from $0.07 to $1.12 an hour by size.
  • 2Agents run in isolated microVMs and never see raw secrets, Docker says; availability is listed for Personal and Pro accounts.
  • 3Docker is contributing its Sandbox Kit specification for agent permissions to the CNCF, and says it worked with AWS, Datadog, Palo Alto Networks and others to build Kits for their tools.

The news

Docker Cloud Sandboxes launched on September 24, letting developers run AI coding agents in isolated virtual machines on Docker's cloud, billed by the second from $0.07 an hour, and move work between laptop and cloud with one command.

The service extends Docker Sandboxes, which already run agents on local machines, to Docker-managed compute. Each cloud sandbox is a microVM, a lightweight virtual machine with its own kernel, Docker daemon, network layer and workspace, which Docker says keeps the developer's own files, network and secrets protected if an agent misbehaves. Docker says sessions run for one hour by default and up to 24 hours, letting agents work on long tasks unattended, and a single command moves a project's file system from a laptop to the cloud or back.

Pricing is pay-as-you-go. Docker lists five sizes: Micro, with 1 virtual CPU and 2 GiB of memory, at $0.07 an hour; Small at $0.14; Medium at $0.28; Large at $0.56; and XL, with 16 virtual CPUs and 32 GiB, at $1.12. Volumes, data egress and hosting of public images and Kits are free, local sandboxes stay free, and for a limited time new accounts get $250 in credit. The service requires the pay-as-you-go plan, which is available on Docker Personal and Pro accounts.

Docker is pitching secrets handling and network policy as the main controls. Keys and tokens are stored once and injected by a proxy on each request, so agents never see the actual secret, which Docker says guards against prompt injection. Teams can define which endpoints an agent may reach, and Docker said centralized governance through Docker AI Governance is coming. Pre-built Kits support Claude Code, Codex, Copilot, Antigravity, Open Code and Hermes.

Alongside the launch, Docker said it is bringing its Sandbox Kit specification to the Cloud Native Computing Foundation (CNCF) under the Apache 2.0 license. A Kit is a standard OCI container image that bundles an agent with the tools it uses and a typed declaration of the hosts, credentials and volumes it wants to access. Docker said it has worked with AWS, Box, Datadog, Dynatrace, JFrog, NanoClaw, OpenClaw, Palo Alto Networks, Snyk and others to build Kits for their tools, and CNCF chief technology officer Chris Aniszczyk welcomed the move. Techzine quoted Docker president Mark Cavage saying agentic workflows require a fundamentally different approach to isolation.

The numbers

Hourly price range by sandbox size
$0.07 (1 vCPU) to $1.12 (16 vCPU)
Maximum session length
24 hours
Free credit for new accounts (limited time)
$250
Cost of a 24-hour XL session at list price
$26.88

Why CEOs should care

For engineering leaders, the draw is letting agents run long jobs without tying up laptops or exposing them. Before approving use, check which account tiers are covered: Docker lists Personal and Pro, so teams on business plans should confirm availability, administration and billing controls. Ask how sandbox activity is logged and whether those logs can feed your existing security and cost tools.

CFOs should model the metering. At list prices, an XL sandbox running a full 24-hour session costs $26.88, and a default Small sandbox costs $3.36 a day. Those amounts are modest per agent but can add up across hundreds of developers running agents overnight. Set budgets and alerts per team, and use the time-limited $250 credit to measure real consumption before committing to wider rollout.

CISOs should welcome the design principle that agents never see raw secrets, but should verify it rather than assume it. Ask Docker for documentation of the proxy architecture, how network policies are enforced and audited, and when Docker AI Governance will be available. If the CNCF specification is adopted widely, agent permissions could become portable across vendors, which would simplify security reviews.

The bigger picture

Developer platforms are racing to become the place where AI agents run safely. Docker's approach, packaging agents and their permissions as ordinary container images, builds on a format enterprises already scan and govern, rather than inventing a new artifact. Docker is also a founding member of the Blueprint Alliance, announced by Okta on September 22, which aims to publish a shared architecture for securing AI agents across vendors.

What’s next

Watch for Docker AI Governance to ship, for Cloud Sandboxes to reach Docker's business tiers, and for the CNCF to formally take up the Sandbox Kit specification. Adoption by the companies Docker built Kits with, and by other vendors, would show whether the format becomes a common way to describe what an agent is allowed to do.

What “Fact-checked” means

Fact-checking means testing a story’s facts against the evidence before it is published. This story went through at least two separate checks before this version was published.

What we checked
Its names, figures, dates, job titles, quotes and who said what were checked against the story’s sources, including its main source where it could be opened. The headline was checked for accuracy and overstatement.
How
A first check reviewed the whole story. If it passed, a second, skeptical check went back to the sources to look for mistakes in the most important facts. If a check flagged the story, it was edited to fix the problems found, and a separate re-check then reviewed the whole story again.
Who
The checks are made with our newsroom’s technology tools, as steps kept separate from the writing, under rules set by our editor, . A story the checks still flag is not published automatically; it is held for the editor, who decides whether it is fixed, published or dropped.
If something is wrong
“Fact-checked” does not mean error-free. If a material error is found after publication, we correct the story and add a note saying what changed. Report an error

How we fact-check →

Companies in this story

DockerAI agentsDeveloper toolsCNCF

Earlier coverage of Okta

All Okta coverage →

Written by

Editor · Technology & Business Writer

Hussein is a writer and business technology enthusiast focused on the intersection of technology, entrepreneurship, finance, artificial intelligence, and digital innovation.

CoversAICybersecurityBig TechSaaSStartupsFintech

How this story was made. Researched and written using our newsroom’s technology tools and fact-checked before publication.

Published by Tech CEO Daily, an independent publication. Masthead · Editorial standards

Free newsletters

The technology briefing for people running businesses.

Daily, weekly, bi-weekly or monthly. You choose.

How often

The Daily Brief · Weekdays, 6 a.m. ET

Free forever. One click to unsubscribe. We never sell your email.