To me, orchestration is not really the core problem. The bigger challenge is handling agent coherency over long periods of time, (drift) so my solution is a living forum-like system where agents shout to one another, document work in items, and follow doctrine handed down by the developer and work against a known specification that's checkable. I have used this workflow in several large projects that MUST be correct, and it works for me. Currently cleaning it up for other users.
Last year (2025), I lost count of how many times I tried using an LLM to set up Docker. It was still the era of prompting, then copy-pasting the response and seeing if it worked... and it almost never did. It’s great to see this new Docker agent. For me, it would be even more appealing to see an agent and a model specialized in Docker working together, capable of proposing advanced configurations and getting them working on the first try.
I tried really hard to make this work for me a couple of weeks ago but it was the brittlest harness out of any that I've used. I'd come back when it's more mature.
Sessions just broke all the time for me. The one time I dug into it, it ended up being a known issue where if codex returned over 10k characters for a turn it breaks the session. Because docker agent does not use protocols like ACP, instead trying to parse Codex's internal state in a brittle manner.
I tried not to do anything too crazy, but even use using an API key in the docker agent natively was getting me sessions that would hang and couldn't be recovered.
Not the most common use case around them: likely meaning that the Codex harness isn’t used that often internally at Docker, is what I would surmise, at least that is how I read it.
I work at another big tech company, and up until recently that would’ve been true for us as well (but it’s changed now, we partnered with OpenAI)
Go doesn't have a good mod/plugin story for harness devs to provide to their users
I say this as a gopher who also has a custom harness written in Go, it's a real challenge compared to the TS setups, but TS plugins are also a security concern
I agree! Comes with the territory of a compiled language I suppose?
I haven't given this much thought (I also just started with golang last year) but I'm assuming the only real path here is to provide extension SDKs in Lua or other languages whose interpreters have been implemented in go.
I think that's what grafana's k6 [1] does with a JS interpreter
Docker Agent is a harness. There is a sandbox mode that can be used to run it in docker sandbox (a VM, not a container). If you don't use sandbox mode then I assume it is running in a container.
If you don't want to use their harness then you wouldn't use docker agent and instead use their `sbx` cli to run the harness of your choice (claude, codex, pi, etc).
I think it will be great if Docker can get people used to using secure VMs. I am developing a similar project (still a work in progress): https://github.com/gregwebs/agent-vm
I've found sbx to be very helpful. really like the sentinel value wrapper they have going so you can add secrets but the model can't see them. Outbound calls get looked up by sentinel value and the real one goes out to whatever API you're auth'ing too. There's other features but just having claude run in a sandbox and easily see what it does and doesn't have access to has been great.
they hope they can annoy and email every person in the org asking for money , same way as they did it with docker.
looks like a weird abstractions. why do i need this if i have modal.com, e2b, cloudflare that use original docker + some toolings around + way to run + isolations on network level.
Docker Agent could be beneficial for research studies. For example, while writing a ML paper about agents I need to rerun experiments so that:
- others can repeat my results
- validate that variability from LLMs is not causing overconfidence in the results
But currently uv is good enough to create isolated, repeatable environments. And it isn't limited to Linux like standard Docker. So when I want to test small samples on my local PC's GPU (Windows or mac) before running on beefier hardware, I can do that easily.
It frustrates me that there's a prisoners dilemma in communicating this to other humans. If I flag it and write it out (as you've done) I've let the author know that they're losing trust and let others know that they should be more skeptical. I've also created the perfect eval data pair for the ai labs. It's deeply frustrating.
There was a brief point in time at the beginning of the internet where if you saw an image online you could be kind of confident that it hadn't been manipulated significantly... But somewhere around the mid to late 2000s it became prudent to just assume any image you've seen online got at least a blemish filter pass through something like Photoshop.
Same thing now with written text. Sometimes you'll be a little bit more or less sure than an llm produced the output but never able to say 100% confidently.
You don't really have to use the docker agent sub-command. docker-agent is a standalone binary. When it was created, though, 1.5 year ago, the idea was that it would be the docker compose for agents (original name was cagent, compose for agents).
But it evolved differently and although it runs very well in docker containers and docker sandboxes, it also runs very well anywhere else.
Docker is rapidly fading into irrelevance now that they have missed their strategic acquisition interval via the Microsoft collab misstep, and now has to hype chase as fewer and fewer people believe in their long term viability as a company.
It was created to be the docker compose for agents. 2 years ago, people, including ourselves, started to mix agentic loops and non agentic components in docker compose files. We created docker agent to make this more powerful.
At the end, the link with docker compose is just the yaml form. Which by the way can be replaced with hcl files or Go code.
Docker Agent predates Docker sandboxes. It was created almost two years ago when not everybody had a AI harness. Nowadays, it does run very well in Docker Sandboxes but it runs also very well anywhere you like.
Nowadays there are only two justifiable public languages you should be using for anything
a) C++
b) Rust
Rust itself is dubious due to abysmal compile times and the fact that the only guarantees it gives you are of security (aka a skill issue). Modern LLMs write C++ that is as safe if not safer than Rust. Any other language choice is objectively wrong.
* For those inquisitive enough the keyword "public" is doing all the heavy lifting here. Pretty much everyone should be developing and using an in-house DSL at this point.
This is an almost rage bait take, but in any case I agree that the models ability to write correct code and fuzz and test that code does make language choice a different tradeoff than it was before.
Interesting seeing other people's approaches to orchestration.
I've been working on Pullboard and just open sourced it: https://github.com/pullboard-dev/pullboard
To me, orchestration is not really the core problem. The bigger challenge is handling agent coherency over long periods of time, (drift) so my solution is a living forum-like system where agents shout to one another, document work in items, and follow doctrine handed down by the developer and work against a known specification that's checkable. I have used this workflow in several large projects that MUST be correct, and it works for me. Currently cleaning it up for other users.
Last year (2025), I lost count of how many times I tried using an LLM to set up Docker. It was still the era of prompting, then copy-pasting the response and seeing if it worked... and it almost never did. It’s great to see this new Docker agent. For me, it would be even more appealing to see an agent and a model specialized in Docker working together, capable of proposing advanced configurations and getting them working on the first try.
I'm honestly getting lost between what primary usecase/workflow each of these is intended for: 1. https://kagent.dev/ 2. https://github.com/kubernetes-sigs/agent-sandbox 3. https://github.com/docker/docker-agent (this project) 4. https://docs.langchain.com/oss/python/deepagents/sandboxes#s... 5. https://www.cloudflare.com/products/sandboxes/
I tried really hard to make this work for me a couple of weeks ago but it was the brittlest harness out of any that I've used. I'd come back when it's more mature.
> bittlest
Sorry, what do you mean there?
Typo for brittlest, most brittle
Correct. Updated the message to brittlest. Thank you.
Would love to know what didn't work for you
Sessions just broke all the time for me. The one time I dug into it, it ended up being a known issue where if codex returned over 10k characters for a turn it breaks the session. Because docker agent does not use protocols like ACP, instead trying to parse Codex's internal state in a brittle manner.
I tried not to do anything too crazy, but even use using an API key in the docker agent natively was getting me sessions that would hang and couldn't be recovered.
In your use case you wanted to control codex from docker agent thus you used our harness integration ( https://docker.github.io/docker-agent/features/harnesses/ ). It was not codex calling docker agent which should work with ACP ( https://docker.github.io/docker-agent/features/acp/ ). We could effectively look at using ACP from docker-agent to control others harnesses if it's useful.
Combination with Codex is indeed not the most common use case around us. I'll see what can be improved. Sorry that it broke your workflow!
How is not using it with the most popular coding agent not a common use case?
Not the most common use case around them: likely meaning that the Codex harness isn’t used that often internally at Docker, is what I would surmise, at least that is how I read it.
I work at another big tech company, and up until recently that would’ve been true for us as well (but it’s changed now, we partnered with OpenAI)
While I love new open source dev (especially in Go!), agent harnesses are turning into JS frameworks from yesteryear.
All the cool kids have one!
You know which one will win for sure. ones with the worst experience.
Vue and svelte are easy to use and learn/adopt. But look what won. React.js.
So whatever the ai agent with the vast user basae will win regardless.
---
I know it's a slippery slope, but given you brought up JS framwork analogy, I had to fall into it
I mean as someone who was there at the time, early React was easy to learn and adopt. It’s complexity came later after it had already won
Now Angular v1, man… if I ever see another digest loop error in my life, I will scream
Coupled with VSCode forks to manage them
none are as great as https://wingman.actor!
jk its trash
Go doesn't have a good mod/plugin story for harness devs to provide to their users
I say this as a gopher who also has a custom harness written in Go, it's a real challenge compared to the TS setups, but TS plugins are also a security concern
I agree! Comes with the territory of a compiled language I suppose?
I haven't given this much thought (I also just started with golang last year) but I'm assuming the only real path here is to provide extension SDKs in Lua or other languages whose interpreters have been implemented in go.
I think that's what grafana's k6 [1] does with a JS interpreter
[1] https://github.com/grafana/k6
curious your thoughts on my approach: https://docs.wingman.actor/extend/plugin-quickstart/
https://docker.github.io/docker-agent/configuration/sandbox/
If, like me, you couldn't find any security-related info on the linked page.
Docker Agent is a harness. There is a sandbox mode that can be used to run it in docker sandbox (a VM, not a container). If you don't use sandbox mode then I assume it is running in a container.
If you don't want to use their harness then you wouldn't use docker agent and instead use their `sbx` cli to run the harness of your choice (claude, codex, pi, etc).
I think it will be great if Docker can get people used to using secure VMs. I am developing a similar project (still a work in progress): https://github.com/gregwebs/agent-vm
I've found sbx to be very helpful. really like the sentinel value wrapper they have going so you can add secrets but the model can't see them. Outbound calls get looked up by sentinel value and the real one goes out to whatever API you're auth'ing too. There's other features but just having claude run in a sandbox and easily see what it does and doesn't have access to has been great.
i remember going through the entire docs of docker sandbox and there was not one mention of attack vectors. did they fix that?
they hope they can annoy and email every person in the org asking for money , same way as they did it with docker.
looks like a weird abstractions. why do i need this if i have modal.com, e2b, cloudflare that use original docker + some toolings around + way to run + isolations on network level.
Docker Agent could be beneficial for research studies. For example, while writing a ML paper about agents I need to rerun experiments so that: - others can repeat my results - validate that variability from LLMs is not causing overconfidence in the results
But currently uv is good enough to create isolated, repeatable environments. And it isn't limited to Linux like standard Docker. So when I want to test small samples on my local PC's GPU (Windows or mac) before running on beefier hardware, I can do that easily.
>What it is, what it isn’t
Yep, open ai sol model wrote that.
It frustrates me that there's a prisoners dilemma in communicating this to other humans. If I flag it and write it out (as you've done) I've let the author know that they're losing trust and let others know that they should be more skeptical. I've also created the perfect eval data pair for the ai labs. It's deeply frustrating.
I think the cat is out of the bag.
There was a brief point in time at the beginning of the internet where if you saw an image online you could be kind of confident that it hadn't been manipulated significantly... But somewhere around the mid to late 2000s it became prudent to just assume any image you've seen online got at least a blemish filter pass through something like Photoshop.
Same thing now with written text. Sometimes you'll be a little bit more or less sure than an llm produced the output but never able to say 100% confidently.
AI is going to eradicate, for good, all trust in the Internet.
That's a benified "not a drawback".
Your probably spare yourself some RSI by inverting this and only writing out a message when you find human generated content on hn
What does this have to do with Docker?
I guess people at Docker wanted to make an agent.
Having it docker branded, I could understand. It’s confusing but the docker brand is strong.
But exposing it as a docker subcommand is very confusing to me.
You don't really have to use the docker agent sub-command. docker-agent is a standalone binary. When it was created, though, 1.5 year ago, the idea was that it would be the docker compose for agents (original name was cagent, compose for agents).
But it evolved differently and although it runs very well in docker containers and docker sandboxes, it also runs very well anywhere else.
It reads to me like chasing trends
That's the economy we've always been in. X is popular, if your company doesn't have a solution for X you're irrelevant.
that's all docker has been doing for years.
the tools and features certainly indicate so
The quest for staying relevant.
Based on the repo short description and the first sentence of the readme:
It is called 'Docker' as the company, and it has nothing to do with the container technology.
This made me laugh. Not sure why. But the whole situation is very absurd now.
It's the Docker you know and love... with AI!
Docker is rapidly fading into irrelevance now that they have missed their strategic acquisition interval via the Microsoft collab misstep, and now has to hype chase as fewer and fewer people believe in their long term viability as a company.
Great tech. Not a business.
Why can't we set the harness? Seems like the missing piece
Pretty vague
very weird. why does this have dockers name on it? might as well use an agent harness from kohl's or steak n' shake. odd..
It was created to be the docker compose for agents. 2 years ago, people, including ourselves, started to mix agentic loops and non agentic components in docker compose files. We created docker agent to make this more powerful.
At the end, the link with docker compose is just the yaml form. Which by the way can be replaced with hcl files or Go code.
gimmick
What's new or interesting here? Docker's AI story ought to be around sandboxing, yet the word appears nowhere. Oh, and it's YAML, which I despise.
Docker Agent predates Docker sandboxes. It was created almost two years ago when not everybody had a AI harness. Nowadays, it does run very well in Docker Sandboxes but it runs also very well anywhere you like.
> Go
Nowadays there are only two justifiable public languages you should be using for anything a) C++ b) Rust
Rust itself is dubious due to abysmal compile times and the fact that the only guarantees it gives you are of security (aka a skill issue). Modern LLMs write C++ that is as safe if not safer than Rust. Any other language choice is objectively wrong.
* For those inquisitive enough the keyword "public" is doing all the heavy lifting here. Pretty much everyone should be developing and using an in-house DSL at this point.
This is an almost rage bait take, but in any case I agree that the models ability to write correct code and fuzz and test that code does make language choice a different tradeoff than it was before.
Yeah well I'm doing everything in AssemblyScript.