This mixin gives any Docker Sandbox agent access to Kernel cloud browsers. It installs the Kernel CLI, adds a quick-reference guide, permits the required network destinations, and keeps the Kernel API key outside the sandbox.
Docker publishes the kit at docker.io/sbx/kernel-kit from the docker/sbx-kits-contrib repository.
-
Install Docker Sandboxes and sign in by following Docker's getting started guide.
-
Create a Kernel API key, then store it in Docker Sandboxes' host-side secret store:
sbx secret set kernel -
Launch an agent with the kit:
sbx run claude --kit docker.io/sbx/kernel-kit:latest
On first use, sbx asks you to approve injecting the kernel credential into requests to api.onkernel.com. The sandbox receives only a proxy-managed sentinel; the host proxy replaces it with the real key when the request leaves the sandbox.
Validate and inspect the kit before creating a sandbox:
sbx kit validate .
sbx kit inspect .Run the non-destructive checks with:
scripts/smoke.shRun the full smoke test with a disposable Claude sandbox after storing the Kernel credential:
scripts/smoke.sh --createThe full test verifies the CLI, bundled quick-reference guide, proxy-managed environment variable, and an authenticated Kernel API request. Set KEEP_SANDBOX=1 to retain the sandbox for debugging.
Docker Hub publication uses an OCI artifact rather than a container image:
sbx login
sbx kit validate .
sbx kit push . docker.io/onkernel/kernel-kit:latest --signThe Docker Verified Publisher badge is granted at the Docker Hub namespace level. Pushing a kit does not grant the badge; the onkernel namespace must complete Docker's Verified Publisher application separately.
spec.yaml— schema v2 mixin definitionfiles/home/.kernel/quickstart.md— examples installed into the agent's home directoryscripts/smoke.sh— local validation and optional end-to-end test