Docker and CNCF partner on an open spec for agent permissions
Right now your agent’s permissions probably live in somebody’s shell history. Docker’s Sandbox Kit spec packages the agent, its tools and a typed list of everything it is allowed to reach - hosts, credentials, volumes - as an ordinary OCI image, so existing registries, scanners and signing keep working unchanged. Apache 2.0, heading into CNCF governance. Pin the image and you pin the permissions with it.