YOLO Mode, Safely: MicroVM Sandboxes for Any Agent — Rowan Christmas, Docker
Rowan tried to hack himself with his own coding agent. Five prompts later it had found his browser history, his bank accounts and more. Rowan Christmas, product manager at Docker, shows why harness-level guardrails aren't enough to protect your machine from your own agent, and how microVM sandboxes give you security by design. He demos Docker Sandboxes (sbx): one command spins up an isolated VM with its own kernel, filesystem isolation, secret placeholders, default-deny networking and a full audit trail. It works with Claude Code, Codex or anything else. He also previews agent identity, delegation chains and policy-based governance. In this talk: • How a coding agent with default permissions can surface sensitive data on your laptop • Why microVMs beat harness-level guardrails • Running any agent in a sandbox with a single command • Governance: network allow/deny, filesystem rules, MCP catalogs and what's coming next SPEAKER Rowan Christmas, Product Manager, Docker LinkedIn: https://www.linkedin.com/in/rowanchristmas/ LINKS Docker Sandboxes: https://www.docker.com/products/docker-sandboxes/ Docs: https://docs.docker.com/ai/sandboxes/ sbx releases (GitHub): https://github.com/docker/sbx-releases Docker: https://www.docker.com/ CHAPTERS 0:00 Intro 0:12 Hi from Docker 0:27 Docker Sandboxes (sbx) 0:52 Is your coding harness protecting you? 1:22 Hacking myself: from browser history to bank data 2:32 The security team's alert 3:22 Five prompts was all it took 3:47 MicroVMs: secure by design 5:07 Demo: claude vs sbx run claude 5:47 The same attack, sandboxed 6:12 Network egress blocked by default 6:47 Every Docker developer codes in sandboxes 7:07 Why the harness level isn't enough 7:52 Agent identity and delegation chains 8:46 Governance controls 9:11 Coming next: L7 and per-repo controls 9:46 Install and run any agent 10:31 Read-only mounts for related repos 10:56 Wrap-up Recorded at the AI Engineer World's Fair 2026 in San Francisco. Subscribe for more talks from the engineers building with AI. AI Engineer: https://ai.engineer YouTube: https://www.youtube.com/@aiDotEngineer X: https://x.com/aiDotEngineer LinkedIn: https://www.linkedin.com/company/aidotengineer/ #AISecurity #Docker #AIEngineer




Join the discussion
Sign in to join the discussion
Sign in