Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
29 changes: 24 additions & 5 deletions content/manuals/ai/sandboxes/configuration/credentials.md
Original file line number Diff line number Diff line change
Expand Up @@ -274,11 +274,30 @@ interact with GitHub APIs on your behalf.

### SSH agent

If your host has an SSH agent and `SSH_AUTH_SOCK` is set, Docker Sandboxes
forwards the agent into the sandbox and sets `SSH_AUTH_SOCK` there. The
private keys stay on your host. Processes inside the sandbox can request
signatures from the forwarded agent, but they can't read or copy the private
key.
SSH agent forwarding is enabled by default. When `SSH_AUTH_SOCK` is set,
Docker Sandboxes uses the value from the client that creates, starts, or joins
each sandbox. It forwards that agent into the sandbox and sets `SSH_AUTH_SOCK`
there.

Run `sbx setup` to configure forwarding and choose which socket to use:

```console
$ sbx setup
```

In the SSH agent step, you can disable forwarding, use each client's current
`SSH_AUTH_SOCK`, or set a fixed socket path for every sandbox. A fixed path is
useful for agents that use a custom socket, such as the 1Password SSH agent.

After changing forwarding or the socket selection, restart the daemon so
existing sandboxes use the new configuration:

```console
$ sbx daemon restart
```

The private keys stay on your host. Processes inside the sandbox can request
signatures from the forwarded agent, but they can't read or copy a private key.

Use SSH agent forwarding for Git operations over SSH and SSH-based commit
signing. The signing key must be loaded in the host SSH agent for sandboxed
Expand Down
6 changes: 6 additions & 0 deletions content/manuals/ai/sandboxes/security/isolation.md
Original file line number Diff line number Diff line change
Expand Up @@ -233,4 +233,10 @@ environment variables or files inside the sandbox unless you explicitly set
them. This means a compromised sandbox cannot read API keys from the local
environment.

SSH agent forwarding is enabled by default. Private keys stay on the host, but
any process inside the sandbox can ask the forwarded agent to authenticate or
sign data. Docker Sandboxes forwards only sockets it recognizes as SSH agents.
A sandbox receives no SSH agent when forwarding is disabled, the configuration
is unavailable, or the selected socket can't be used.

For how to store and manage credentials, see [Credentials](../configuration/credentials.md).
12 changes: 12 additions & 0 deletions content/manuals/ai/sandboxes/troubleshooting.md
Original file line number Diff line number Diff line change
Expand Up @@ -273,6 +273,18 @@ the command again:
Docker Sandboxes can sign Git commits with SSH keys from your host agent.
For setup steps, see [Commit signing](workflows/git.md#commit-signing).

Forwarding is enabled by default. Run `sbx setup` and confirm that forwarding
is enabled and the SSH agent row shows the intended socket mode:

```console
$ sbx setup
```

If you use each client's current `SSH_AUTH_SOCK`, reconnect from a shell where
it points to the intended agent. If you use a fixed socket, confirm that the
configured path points to an active host agent. After changing forwarding or
the socket selection, run `sbx daemon restart`.

If `ssh-add -L` prints `The agent has no identities.`, the sandbox can reach
the forwarded agent, but the host agent doesn't have a loaded key. Load the
signing key into your host SSH agent:
Expand Down
10 changes: 6 additions & 4 deletions content/manuals/ai/sandboxes/workflows/git.md
Original file line number Diff line number Diff line change
Expand Up @@ -183,11 +183,13 @@ yourself after reviewing the changes.

## Commit signing

Sandboxes forward your host SSH agent into the sandbox, so the agent can
sign commits with your SSH key without the private key ever leaving your
host.
SSH agent forwarding is enabled by default. When `SSH_AUTH_SOCK` is set,
sandboxes forward your host SSH agent into the sandbox, so the agent can sign
commits with your SSH key without the private key ever leaving your host. If
you turned off forwarding or use a fixed SSH agent socket, see
[SSH agent configuration](../configuration/credentials.md#ssh-agent).

1. On your host, make sure the signing key is loaded in your SSH agent:
1. Make sure the signing key is loaded in your host SSH agent:

```console
$ ssh-add ~/.ssh/id_ed25519
Expand Down