> Markdown version of [/events/world-congress-2026-north-america/sessions/1762-docker-sandboxes](https://www.wearedevelopers.com/events/world-congress-2026-north-america/sessions/1762-docker-sandboxes). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Docker sandboxes: protect your secrets, tokens, and personal data from AI agent mistakes - **Event:** World Congress 2026 North America ## Description The number of cyber attacks and security risks related to Coding Agents has sky rocketed. AI coding agents like Claude Code, Codex CLI, and Gemini CLI don’t behave like your typical developer tools. They install system packages, modify configurations, delete files, run services, and even spin up Docker containers, often requiring constant permission prompts or risky access to your host machine. This talk explores Docker Sandboxes as a new execution model for autonomous coding agents. Built on microVM-based isolation, Docker Sandboxes provide disposable, agent-safe environments where coding agents can run unattended while remaining fully isolated from the host system. We’ll walk through why traditional approaches like OS sandboxing, containers, and full virtual machines, break down for agent workflows, and how Docker Sandboxes combine the developer experience of containers with the hard security boundaries of VMs. Using live examples, we’ll show how agents can safely run Docker-in-Docker, install dependencies, access only the project workspace, and be reset instantly. By the end of this session, you’ll have a clear mental model for when and how to use Docker Sandboxes to unlock higher levels of agent autonomy without compromising safety, security, or developer experience. ## Speaker ### [Kristiyan Velkov](https://www.wearedevelopers.com/@kristiyan-velkov) Front-End Advocate | Speaker | AI & DevOps | Docker Captain | Cursor Ambassador | DevReal | Tech Blogger | Book Author ## Related talks at this congress - [rm -rf: Horror Stories From Unsandboxed AI Agents (and How Docker Fixes This)](https://www.wearedevelopers.com/events/world-congress-2026-north-america/sessions/1718-rm-rf-horror-stories) — Rishab Kumar - [Stop Running Mystery Meat in Production](https://www.wearedevelopers.com/events/world-congress-2026-north-america/sessions/1726-stop-running-mystery) — Jeroen van Erp - [How Docker caught a supply chain attack in 83 minutes](https://www.wearedevelopers.com/events/world-congress-2026-north-america/sessions/1755-how-docker-caught-a) — Khushboo Verma - [Securing AI Agent Infrastructure: Identity, Attestation, and Trust at Scale](https://www.wearedevelopers.com/events/world-congress-2026-north-america/sessions/1432-securing-ai-agent) — Abdel Fane ## Watch remotely Can’t make it to San José? Watch this session live with Pro. You also get: - All full videos, bookmarks, and playlists - World Congress livestreams [See pricing](https://www.wearedevelopers.com/pricing) ## Links - [Get tickets](https://www.wearedevelopers.com/world-congress-north-america/tickets)