A hands-on workshop.
Giving a coding agent free rein is terrifying on your laptop and liberating inside a sandbox. In this hands-on workshop you'll let an agent run wild — install packages, spin up servers, rebuild from scratch — inside an isolated microVM that can never touch your host.
You'll build and ship a real Next.js app end to end, from an empty project, by prompting the agent: give it a role with a skill, open the network policy domain by domain, hand it a secret that never enters the VM, forward a port to see it live, steer it in a tight feedback loop, and ship from your machine.
The app is just the vehicle; the workflow is the point. Bring a laptop and leave knowing how to build anything with an agent — safely, and fast.
Based on the blog post Building a Real App Inside a Docker Sandbox, and inspired in shape by testcontainers/workshop-go.
Now Showing — a small Next.js + TypeScript dashboard that shows the movies trending on TMDB this week. You don't clone it; you build it from scratch by prompting the agent. It's deliberately minimal, but real enough to exercise every part of the sandbox workflow:
- it calls an external API → you'll meet the network policy,
- that API is token-gated → you'll inject a custom secret that never enters the sandbox,
- it runs a dev server → you'll use port forwarding to see it,
- it benefits from richer context → you'll attach a host-side fetch MCP server that reaches past the sandbox's network policy,
- it grows a stateful feature (favorites) → you'll run Redis on the sandbox's own Docker daemon and test it with Testcontainers and Playwright, and
- it has an obvious backlog → you'll iterate with the agent and ship.
- How a Docker Sandbox isolates a coding agent (a microVM with its own daemon, filesystem, and network) so it can run autonomously without touching your host — and how to prove that isolation is structural, not trust-based.
- How to run the whole workshop on an isolated
sbxdaemon with--app-name, so its policies, secrets, and sandboxes never mix with the ones you work in — and how to throw the lot away in one command when you're done. - How to govern the agent's network access domain by domain with
sbx policy. - How to hand the agent a secret that stays on your host and never enters the
VM, with
sbx secret set-custom. - How to give the agent a role with a skill so it works like a product owner, not a code vending machine.
- How to forward a port and get real-time visual feedback in your browser.
- How to attach an MCP server via
sbx mcp— a tool that runs on your host, so what it fetches isn't bound by the sandbox's network policy even though the agent's own requests still are. - How to run real backing services (Redis), integration tests (Testcontainers), and browser-based GUI tests (Playwright) on the sandbox's own Docker daemon — no host setup.
- How to use a kit to bootstrap a sandbox with packages and network rules in one line.
- How to swap the harness — the sandbox is a machine with an SSH door, not an appliance welded to one agent UI. You'll drive it from T3 Code as well as the terminal, and learn what each harness puts inside the VM.
- The feedback loop that makes agent-assisted development precise: prompt → watch → check → steer → ship.
- macOS ARM with Homebrew, or Windows 11 (Intel or AMD processor) with WinGet, or Linux Ubuntu with KVM hardware virtualizarion supported and turned on.
- A Claude account to log the agent in. A fresh sandbox has no credentials: the
first time you attach you'll get an empty Claude prompt with a not-logged-in message,
and you type
/loginthere (Step 3). AnANTHROPIC_API_KEYworks too, if you'd rather set it up in advance. - A free TMDB account and the v4 API Read Access
Token — the long JWT starting
eyJ, not the short hex "API Key (v3 auth)" listed above it on the same page. Only the v4 token can work here (Step 2 explains why). Get this before you start: the request form needs email verification plus real contact details (name, postal address, phone), so budget 5–10 minutes. Step 1 has a field-by-field guide. - A GitHub account, for the ship step.
- Comfort with the terminal. You do not need to be a Next.js expert — the agent writes the code; you drive.
- Docker. You do not need to start Docker now — Step 10 runs an MCP server as a container on your host, and it fails with an unhelpful error if Docker isn't running. (Steps 0–9 don't need it, so it's easy to get a long way in before noticing.)
Work through the steps in order. Each is self-contained, builds on the last, and ends at a state you can verify. The prompts you give the agent are in each step.
| # | Step | What you'll do |
|---|---|---|
| 0 | The Big Picture | The microVM mental model and a one-screen map of the pillars |
| 1 | Install and Log In | Install sbx, isolate the workshop's daemon with --app-name, log in, pick Balanced, get a TMDB token |
| 2 | Set the API Token as a Secret | sbx secret set-custom — the token never enters the VM |
| 3 | Create the Sandbox | sbx create a microVM with the agent attached |
| 4 | Prove Isolation | Verify the isolation is structural — workspace sync, unreachable host files, non-exfiltrable secrets |
| 5 | Establish the Foundation | Give the agent a product-owner role via a skill |
| 6 | Scaffold the App | One prompt builds the Next.js + TS app |
| 7 | Forward the Port | See the app in your host browser |
| 8 | Open the Network | Allow TMDB's domains, one at a time — the movies appear |
| 9 | Iterate | Prompt, watch, check, steer — and isolating a bigger change on a branch |
| 10 | Attach a Fetch MCP | Register mcp/fetch via sbx mcp; give the agent host-side web fetch that bypasses the sandbox network policy |
| 11 | Add Favorites with Redis | Run Redis via the sandbox's own Docker daemon; persist state |
| 12 | Integration Tests with Testcontainers | Test against real, ephemeral Redis — reliable, isolated |
| 13 | GUI Tests via Playwright Kit | Headless browser tests using a kit — no display server needed |
| 14 | Choose Your Harness | Optional — drive the same sandbox from T3 Code over SSH, and weigh what each harness puts inside the VM |
| 15 | Ship & Wrap-Up | Commit from your host; pause and resume; tear the workshop daemon down; what made it work |
Reference: Appendix — Concepts & Reference —
isolated daemon instances (--app-name), workspace clone mode, kits, network
presets, secrets, and links to the official docs. Read it on demand; you don't need
it to start.
main— the workshop itself: just this README and thedocs/steps. This is all you need to run the workshop; the agent generates the app as you go.solutions— the finished Now Showing implementation plus the docs, as a reference. If your agent goes sideways, compare against this branch. It's maintained as the source of truth; doc changes are backported tomain.
Created by Manuel de la Peña. Built — fittingly — inside a Docker Sandbox. Licensed under MIT.