All Posts

Cloud & DevOps

Docker and Azure Ship Agent Sandboxes the Same Week AWS Launches CloudWatch Omni

Docker and Azure Ship Agent Sandboxes the Same Week AWS Launches CloudWatch Omni

Bhavika J

Editorial Team

Published

Microsoft made Azure Container Apps Sandboxes generally available on 23 September 2026, turning hardware-isolated microVMs for AI agent code into a production service billed by the core-second. A day later Docker launched a hosted version of its own agent sandboxes and said it would take the format it uses to describe an agent's permissions to the Cloud Native Computing Foundation (CNCF).

AWS, in the same week, made CloudWatch Omni generally available, an observability product organized around tracing what applications and AI agents actually did. The three launches sit at different layers of the stack. Taken together, they show vendors treating agent-run code as something to isolate, permission and audit, rather than as one more container workload.

Azure puts agent sandboxes on a production meter

Microsoft's GA announcement follows a public preview that opened in June. Each sandbox is a hardware-isolated microVM with its own Linux kernel, which Microsoft says starts in under a second. Operators decide per sandbox what it can reach, how large it is and how long it lives.

Network control runs through an egress proxy that checks every outbound request against rules by host, domain pattern or CIDR range, and can default to deny. Credentials are injected at the proxy from sandbox-group secrets, so the agent can call a service without ever holding the API key. Snapshots capture memory and disk, letting a configured environment resume instead of rebuilding from scratch.

Billing has three parts, per Microsoft's documentation: vCPU per core-second and memory per GiB-second while a sandbox runs, plus storage for custom disk images at Premium Azure Blob ZRS rates. The OS disk each sandbox boots from is not billed. Microsoft says preview usage passed a million sandboxes created every day and names Templafy and KPMG as users. That figure is Microsoft's own and has not been independently confirmed.

The meter changes the cost question from how many sandboxes a team runs to how long they stay up. An agent idling in a running sandbox still consumes core-seconds, so lifecycle limits and snapshots work as cost controls as much as conveniences.

Docker moves sandboxes to the cloud and permissions to the CNCF

Docker announced Cloud Sandboxes on 24 September at WeAreDevelopers North America. The service extends the microVM isolation Docker already ships for local sandboxes to Docker-managed compute, so an agent can keep working after a developer's laptop shuts down. Docker says the isolation model and command-line tool are identical in both places and one command moves a sandbox between them, though local and cloud sandboxes keep separate secrets, templates and network policies.

Each Cloud Sandbox runs in its own microVM with its own kernel (Docker). Network policies define which endpoints an agent can reach, and a proxy injects stored keys per request so the agent never sees the secret. Compute is billed per second, from $0.07 an hour for a 1 vCPU, 2 GiB Micro size to $1.12 an hour for a 16 vCPU, 32 GiB XL, and a paused sandbox costs nothing. Sessions run for one hour by default and up to 24 hours (Docker, as of 24 September 2026).

The announcement with longer consequences is the Sandbox Kit Spec. A Kit packages an agent, its tools and a typed list of everything it asks to reach, including hosts, credentials and volumes, into one OCI image. Docker says Kits use an extension point OCI already defines rather than a new artifact type, so they build, push, sign and scan like any other image (Help Net Security). The spec is published under Apache 2.0, and Docker has said the formal CNCF submission will follow later this fall (Linux.com). AWS, Box, Datadog, Dynatrace, JFrog and Snyk are among the partners that have built Kits.

What this changes is where an agent's permissions live. Without a shared format they sit across runtime flags, proxy rules and secrets stores. A Kit turns them into a versioned artifact that goes through the same registry, signing and review process as the image itself. For now, Docker Sandboxes is the only runtime enforcing the spec.

The two designs look alike

Side by side, Microsoft's and Docker's products use the same architecture: a microVM with its own kernel, rules on which endpoints the agent can reach, and credentials added by a proxy outside the sandbox. Neither company is selling a new isolation idea. Both are selling a managed version of the same one.

For a buyer, that moves the comparison to operational terms: the billing unit, session limits, where the sandbox runs relative to the data it touches, and whether its permission model is portable. Portability is the question Docker's CNCF move is meant to settle, and it only works if a second runtime adopts the format.

AWS goes after the audit trail

CloudWatch Omni reached general availability on 23 September in US East (N. Virginia), US West (Oregon) and Europe (Ireland). Customers create a space in a central account and see telemetry across their AWS accounts and regions there. It works on telemetry already sent to CloudWatch and accepts OpenTelemetry data from other sources.

Omni discovers services, maps their dependencies and brings the AWS DevOps Agent into investigations to correlate signals (InfoWorld). Teams reach it through a standalone web interface with single sign-on or an IDE extension, rather than only the AWS console. AWS says it can also show telemetry from other clouds, including Azure workloads.

According to AWS's pricing page, Omni charges for telemetry sent, telemetry retained and analysis run. Dashboards and alerts carry no extra charge, query volume up to five times monthly log and span ingestion is included, and eligible accounts get $1,000 in credits for 30 days toward OpenTelemetry ingestion. SiliconANGLE's coverage framed the product around one question: why did the agent do that?

Accepting Azure telemetry is the detail to note. It offers an AWS product as the place to review agent behavior even when the workload runs on a competitor's platform, a direct appeal to multicloud teams.

What to watch

Docker's formal CNCF submission of the Sandbox Kit Spec, which the company has placed later this fall. The real test is whether Microsoft, AWS or another sandbox provider commits to enforcing Kits in its own runtime.

KubeCon + CloudNativeCon North America, which runs 9 to 12 November in Salt Lake City with a new AI Inference + Agentic track (CNCF). It is the first major CNCF event since the Kit announcement.

Omni's region list, currently three. Organizations with data residency requirements outside the US and Ireland will need more regions before they can centralize telemetry there.

Sources

  • Microsoft. "Azure Container Apps Sandboxes, Now Generally Available." 2026. https://techcommunity.microsoft.com/blog/appsonazureblog/azure-container-apps-sandboxes-now-generally-available/4559125
  • Microsoft. "Azure Container Apps Sandboxes overview." 2026. https://learn.microsoft.com/en-us/azure/container-apps/sandboxes-overview
  • Docker. "Docker Launches Cloud Sandboxes, Extending Secure AI Agent Isolation Beyond the Laptop." 2026. https://www.globenewswire.com/news-release/2026/09/24/3368595/0/en/docker-launches-cloud-sandboxes-extending-secure-ai-agent-isolation-beyond-the-laptop.html
  • Docker. "Introducing Cloud Sandboxes: Start on Your Laptop, Finish in the Cloud." 2026. https://www.docker.com/blog/introducing-cloud-sandboxes-start-on-your-laptop-finish-in-the-cloud/
  • Docker. "Docker and CNCF partner on an open spec for agent permissions." 2026. https://www.docker.com/blog/docker-sandbox-kit-spec-cncf/
  • Linux.com. "Docker Commits to Bringing the Sandbox Kit Spec to the CNCF." 2026. https://www.linux.com/featured/docker-commits-to-bringing-the-sandbox-kit-spec-to-the-cncf/
  • Help Net Security. "Docker introduces OCI-based Kits to package agents and their access." 2026. https://www.helpnetsecurity.com/2026/09/25/docker-launches-cloud-sandboxes/
  • AWS. "Amazon CloudWatch Omni: AI-first observability for agents and applications." 2026. https://aws.amazon.com/about-aws/whats-new/2026/09/amazon-cloudwatch-omni-ai/
  • AWS. "Amazon CloudWatch Omni pricing." 2026. https://aws.amazon.com/cloudwatch/omni/pricing/
  • InfoWorld. "AWS launches CloudWatch Omni to unify observability for AI agents and applications." 2026. https://www.infoworld.com/article/4225120/aws-launches-cloudwatch-omni-to-unify-observability-for-ai-agents-and-applications.html
  • SiliconANGLE. "AWS CloudWatch Omni goes after the hardest question in agentic AI: why did the agent do that?" 2026. https://siliconangle.com/2026/09/27/aws-cloudwatch-omni-goes-after-the-hardest-question-in-agentic-ai-why-did-the-agent-do-that/
  • CNCF. "CNCF Reveals KubeCon + CloudNativeCon North America 2026 Schedule, Adds New AI Inference + Agentic Track." 2026. https://www.cncf.io/announcements/2026/08/10/cncf-reveals-kubecon-cloudnativecon-north-america-2026-schedule-adds-new-ai-inference-agentic-track/