Coder powers secure, scalable development across key industries — automotive, finance, government, and technology — enabling faster builds, tighter compliance, and seamless AI adoption in enterprise-grade cloud environments.
Runtime & Permission Requirements for Running Boundary in Docker
This section describes the Linux capabilities and runtime configurations
required to run Agent Firewall with nsjail inside a Docker container.
Requirements vary depending on the OCI runtime and the seccomp profile in use.
1. Default runc runtime with CAP_NET_ADMIN
When using Docker's default runc runtime, Agent Firewall requires the
container to have CAP_NET_ADMIN. This is the minimal capability needed for
configuring virtual networking inside the container.
Docker's default seccomp profile may also block certain syscalls (such as
clone) required for creating unprivileged network namespaces. If you encounter
these restrictions, you may need to update or override the seccomp profile to
allow these syscalls.
2. Default runc runtime with CAP_SYS_ADMIN (testing only)
For development or testing environments, you may grant the container
CAP_SYS_ADMIN, which implicitly bypasses many of the restrictions in Docker's
default seccomp profile.
Agent Firewall does not require CAP_SYS_ADMIN itself.
However, Docker's default seccomp policy commonly blocks namespace-related
syscalls unless CAP_SYS_ADMIN is present.
Granting CAP_SYS_ADMIN enables Agent Firewall to run without modifying the
seccomp profile.
⚠️ Warning: CAP_SYS_ADMIN is extremely powerful and should not be used in
production unless absolutely necessary.
3. sysbox-runc runtime with CAP_NET_ADMIN
When using the sysbox-runc runtime (from Nestybox), Agent Firewall can run
with only:
CAP_NET_ADMIN
The sysbox-runc runtime provides more complete support for unprivileged user
namespaces and nested containerization, which typically eliminates the need for
seccomp profile modifications.
Docker Seccomp Profile Considerations
Docker's default seccomp profile frequently blocks the clone syscall, which is
required by Agent Firewall when creating unprivileged network namespaces. If
the clone syscall is denied, Agent Firewall will fail to start.
To address this, you may need to modify or override the seccomp profile used by
your container to explicitly allow the required clone variants.
You can find the default Docker seccomp profile for your Docker version here
(specify your docker version):