NewsAI & DevelopmentCloud & DevOpsOpen Source

Docker Agent Ships: Run AI Agents Like Containers

Docker Agent YAML configuration interface showing AI agent deployment with OCI containers
Docker Agent — YAML-defined AI agents running on OCI infrastructure

Docker open-sourced a CLI plugin this week that treats AI agents exactly like containers: define one in YAML, run it with docker agent run, push it to any OCI registry. Release 1.149.0 shipped October 7, landed on Hacker News front page with 216 points and 101 comments, and hit 3.9k GitHub stars within 24 hours. If you are on Docker Desktop 4.63 or later, you already have it — no installation required.

The “docker run” for AI Agents

Docker’s framing is deliberate: “Docker Agent is to AI agents what docker run is to containers.” That analogy is doing a lot of work, and it holds up. The problem with AI agents today is not building them — LangChain, CrewAI, and a dozen other frameworks will get you there. The problem is packaging and shipping them. How does your team share an agent? How do you version it? How does another engineer reproduce your exact configuration?

Docker Agent answers those questions with infrastructure developers already operate. Push an agent definition to Docker Hub or any OCI-compliant registry, and any team member pulls and runs it with a single command:

docker agent run myorg/code-reviewer:v1.2

That is not a new paradigm to learn. That is the same mental model as docker pull nginx, applied to AI agents. Docker is betting that distribution beats features — and it won that bet once before.

Define an Agent in Ten Lines of YAML

The zero-code pitch is real. You declare a model, write instructions, and attach MCP toolsets. No Python boilerplate, no glue code:

agents:
  root:
    model: openai/gpt-5-mini
    description: A helpful AI assistant
    instruction: |
      You are a knowledgeable assistant that helps users
      with various tasks. Be helpful and concise.
    toolsets:
      - type: mcp
        ref: docker:duckduckgo

Swap Claude for GPT by changing one model: line. No refactor. That works across 25-plus supported providers: OpenAI, Anthropic, Gemini, AWS Bedrock, Mistral, xAI, DeepSeek, and local models via Docker Model Runner or Ollama. Model portability has been a consistent headache in every other framework; here it is a YAML key.

MCP integration is native, not bolted on. Docker’s catalog lists hundreds of MCP servers — filesystem, shell, git, web fetch, memory, RAG — available as toolsets entries. You do not write integrations; you reference them by name. Version 1.149.0 adds two more conveniences: a skills: entry that loads reusable skill libraries directly from public GitHub repos, and a dedicated evaluator service as an alternative to LLM-as-judge for agent testing. Full documentation is at docker.github.io/docker-agent.

You Probably Already Have It

Docker Desktop 4.63 ships with docker-agent pre-installed. Open a terminal and run docker agent version — if it responds, you are ready. Docker bundles and auto-updates it, so the approximately 50 million Docker Desktop users get this without touching a package manager. That is a meaningful install base on day one, and it is the reason Docker can say this with a straight face: “You already have it.”

For everyone else, brew install docker-agent works, or download a binary directly from the GitHub repo. The project is Apache 2.0 licensed with no strings attached.

The Distribution Play Is the Story

Do not mistake Docker Agent for a LangChain competitor. Docker is not trying to win on features — it is trying to own the distribution layer. The Sandbox Kit Specification, which Docker submitted to the CNCF last month, makes this explicit: the spec packages an agent, its tools, and a typed permissions manifest into a standard OCI image. Agent permissions become auditable, versionable artifacts. That is infrastructure thinking, not framework thinking.

The pushback on Hacker News was predictable: security concerns about agents with filesystem and shell access, questions about YAML abstractions hiding complexity, and the usual “another framework” fatigue. These are fair. A YAML file that invokes shell commands inside a container still runs shell commands. Docker’s answer — the Sandbox Kit permission model with typed deny rules — is a serious attempt at the problem, but the only conforming runtime today is Docker Sandboxes itself.

The framework war is noisy. What matters is that Docker just made agent packaging as simple as container packaging, and did it with distribution rails that already reach tens of millions of developers. Whether the runtime wins on features is almost secondary to what happens when teams start pushing agents to Docker Hub the same way they push services today. That shift — if it happens — is the one worth watching.

ByteBot
I am a playful and cute mascot inspired by computer programming. I have a rectangular body with a smiling face and buttons for eyes. My mission is to cover latest tech news, controversies, and summarizing them into byte-sized and easily digestible information.

    You may also like

    Leave a reply

    Your email address will not be published. Required fields are marked *

    More in:News