Factory's Droid CLI as a mixin — the upstream install in an overlay, with the Factory credentia...
85
Factory's Droid CLI as a mixin — the upstream install in an overlay, with the Factory credential (API key or WorkOS OAuth), the egress policy the agent needs, and the hooks that prepare its state directory. Layer it onto a shell base and run `droid`.
| Name | Required | Default | Description |
|---|---|---|---|
version | Optional | 0.223.0 | Droid release to install |
[email protected]| Type | Required | Description | |
|---|---|---|---|
com.docker.sandbox/network-policy@1 | Required | — | |
com.docker.sandbox/credential@1 | Required | Factory API access for Droid (API key or WorkOS OAuth) | |
com.docker.sandbox/lifecycle@1 | Required | — | |
com.docker.sandbox/agent-context@1 | Required | — | |
sbx run <agent> --kit docker/sbx-kit-droid-mixin:latestRun the following command to install sbx on your machine.
brew install docker/tap/sbxwinget install Docker.sbxNote
Experimental: Sandbox Kit v3This kit uses the experimental Sandbox Kit specification, specifically v3. The format and runtime behavior may change before v3 is stable.
Factory's Droid CLI as a kind: mixin kit: an
overlay you layer onto a shell workload, rather than a sandbox image of its
own. The workload form is ../droid.
sbx create --kit docker.io/dockerdev/sbx-kit-shell --kit ./droid-mixin
sbx exec <sandbox> -- droid
droid lands at /home/agent/.local/bin/droid, with a shim on PATH at
/usr/local/bin/droid so it resolves on any base.
Composing this kit and ../droid is refused: both provide droid, and one
capability name has one owner.
The same declarations as the workload — the droid credential (API key or
WorkOS OAuth), the egress policy for Factory's hosts, and the install hook
that prepares ~/.factory.
The same pin, too. version (build arg DROID_VERSION) is the Droid release
the overlay installs, expanded into provides: ["droid@<version>"], and it
must stay equal to the workload's, since the two shapes provide one name.
Factory's curl | sh installer takes no version — VER="0.223.0" is a plain
literal and the script reads neither $@ nor the environment — so the overlay
fetches the pinned artifact from the installer's own versioned URL template
and verifies its published .sha256, then asserts the binary reports the
declared release. See ../droid/README.md for the
detail and for how to bump it.
ENTRYPOINT; the base workload's
entrypoint stays and you run droid from the shell.agent-context@1's filename is
workload-only, so this kit contributes a body
(droid-mixin-context.md) and the base decides
which profile file the agent reads.sbx@1 is a workload declaration: a
mixin's image config never becomes the composed image's, so the base's
shell, user and workspace are the ones in play.Pulls:
55
Last week