> Markdown version of [/videos/100541-one-boundary-for-the-agentic-era](https://www.wearedevelopers.com/videos/100541-one-boundary-for-the-agentic-era). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # One Boundary for the Agentic Era Are autonomous AI agents exposing your infrastructure to unseen supply chain risks? Discover how Docker sandboxes and the new Kit specification enforce secure, observable boundaries as code. - **Speakers:** [Mark Lechner](https://www.wearedevelopers.com/@mark-lechner) - **Event:** World Congress 2026 North America - **Published:** September 26, 2026 - **Duration:** 32:01 - **URL:** https://www.wearedevelopers.com/videos/100541-one-boundary-for-the-agentic-era ## Summary As AI agents transition from theoretical tools to autonomous entities operating at machine speed, organizations face a critical escalation in supply chain risk. Agents tasked with open-ended objectives often inherit broad production access or human credentials, amplifying the danger of misconfigurations, unauthorized API calls, or malicious package installations. Without a structural containment strategy, the industry remains largely blind to agentic activity, unable to definitively trace which workload executed a sensitive operation or why an agent deviated from its intended purpose. To address this visibility and security gap, Docker introduces a unified execution boundary using Docker sandboxes (SBX). By running agents inside isolated micro-VMs with dedicated Linux kernels, security teams gain a verifiably secure perimeter where workspace sharing and network access become explicit, intentional grants. A key architectural advantage is credential proxying, which allows an agent to authenticate requests against internal registries or external APIs without ever possessing the underlying secrets. This effectively neutralizes threats like info stealers while maintaining the agent's operational utility. The operational cornerstone of this methodology is the new Kit specification, an open standard that extends the familiar Dockerfile concept to define agent capabilities as code. Security teams can explicitly prescribe layer 7 network policies, expected endpoints, and trusted components upfront. Because agent behaviors are systematically declared, CI/CD deployments can dynamically generate precise monitoring and SIEM alerting rules. This shifts the paradigm from analyzing black-box agent outputs to orchestrating fully observable, context-aware workloads with enforced access boundaries. **Keywords:** agentic workload security, Docker sandboxes, AI supply chain risk, workload execution boundaries, credential proxying, Kit specification, autonomous agent observability, SIEM integration pipeline, layer 7 network policies, configuration as code, CI/CD security integration, API key isolation, micro-VM sandboxing, identity attribution, malicious agent containment, open-ended task constraints ## Chapters 1. **Security risks of delegating agency to autonomous systems** (00:00) — Delegating open-ended tasks to autonomous agents amplifies existing access vulnerabilities and persistence risks. 1. **Establishing an isolated execution boundary for agents** (02:09) — Isolating agent workloads within a dedicated environment limits the impact of unexpected or malicious actions. 1. **Enforcing network access and securing credential injection** (05:00) — Enforcing network policies outside the workload ensures malicious tools cannot compromise host credentials or services. 1. **Observing agent behavior and investigating unexpected access** (07:43) — Correlating workload identity and purpose with access logs enables accurate attribution of autonomous actions. 1. **Evaluating agent artifacts with verified building blocks** (10:30) — Reusing evidence from verified base components focuses security reviews entirely on newly generated outputs. 1. **Simulating agent interactions within an isolated runtime** (12:27) — Setting up a secure sandbox environment demonstrates how bounded agents interact with local registries and APIs. 1. **Defining agent capabilities using configuration as code** (16:57) — Managing agent manifests as code provides implicit observability and dynamically generates security monitoring rules. 1. **Troubleshooting sandbox deployments and credential configuration failures** (22:11) — Unexpected expired credentials and configuration challenges illustrate the complexities of debugging autonomous agent deployments. 1. **Monitoring application layer policies and dynamic alerting** (27:13) — Collecting network logs from the sandbox daemon enables dynamic alerting and precise attribution for agentic events. ## Related Moments - [Mitigating operational risks through robust agent sandboxing](https://www.wearedevelopers.com/videos/100448-don-t-kill-my-vibes-simple-steps-to-stay-secure-when-vibe-coding) (from "Don’t kill my Vibes - Simple Steps to Stay Secure when Vibe Coding") - [Securing agent interactions using persistent identity and sandboxed environments](https://www.wearedevelopers.com/videos/100380-loop-engineering-in-the-wild-a-live-multi-agent-coding-session) (from "Loop Engineering in the Wild: A Live Multi-Agent Coding Session") - [Evaluating security risks and capabilities of the agentic web](https://www.wearedevelopers.com/videos/1328-how-to-avoid-llm-pitfalls-mete-atamel-and-guillaume-laforge) (from "How to Avoid LLM Pitfalls - Mete Atamel and Guillaume Laforge") - [Reference architecture for secure agent deployments](https://www.wearedevelopers.com/videos/100038-the-day-the-chatbot-asked-for-sudo) (from "The day the chatbot asked for sudo") - [Demystifying the core technical layers of agent architectures](https://www.wearedevelopers.com/videos/100269-beyond-the-benchmark-how-to-evaluate-ai-agents-in-the-real-world) (from "Beyond the Benchmark: How to Evaluate AI Agents in the Real World") - [Implementing security through core software engineering principles](https://www.wearedevelopers.com/videos/100521-the-next-wave-of-agents-what-s-real-what-s-next-and-what-matters) (from "The Next Wave of Agents: What’s Real, What’s Next, and What Matters") ## Related Articles - [ I Gave a Video Editor More Autonomy Than a Trading Bot. On Purpose.](https://www.wearedevelopers.com/magazine/773-i-gave-a-video-editor-more-autonomy-than-a-trading-bot-on-purpose) - [What is Agentic Programming and Why Should Developers Care?](https://www.wearedevelopers.com/magazine/625-what-is-agentic-programming-and-why-should-developers-care) - [Never delegate the understanding](https://www.wearedevelopers.com/magazine/749-never-delegate-the-understanding) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) ## Related Jobs - [Senior Software Engineer, Sandboxes (Eu Or East Coast Preferred)](https://www.wearedevelopers.com/jobs/ext/2161904-senior-software-engineer-sandboxes-eu-or-east-coast-preferred) at **Docker, Inc.** - [Senior Software Engineer, Sandboxes (Eu Or East Coast Preferred)](https://www.wearedevelopers.com/jobs/ext/2145616-senior-software-engineer-sandboxes-eu-or-east-coast-preferred) at **Docker, Inc.** - [Senior Software Engineer, Sandboxes](https://www.wearedevelopers.com/jobs/48460-senior-software-engineer-sandboxes) at **Docker, Inc.** - [Senior Software Engineer, Sandboxes (Eu Or East Coast Preferred)](https://www.wearedevelopers.com/jobs/ext/2145730-senior-software-engineer-sandboxes-eu-or-east-coast-preferred) at **Docker, Inc.** - [Senior Software Engineer, Sandboxes (Eu Or East Coast Preferred)](https://www.wearedevelopers.com/jobs/ext/2159298-senior-software-engineer-sandboxes-eu-or-east-coast-preferred) at **Docker, Inc.** - [Principal Solutions Architect, Professional Services](https://www.wearedevelopers.com/jobs/ext/2747556-principal-solutions-architect-professional-services) at **Docker, Inc.**