This release adds 3 notable features for engineering teams evaluating rollout.
✓ No known CVEs patched in this version
Topics
+13 more
Summary
AI summaryUpdates https://github.com/footprintai/containarium/releases/download/v0.31.0/containarium-windows-amd64.exe, https://kind.sigs.k8s.io/, and PowerShell across a mixed release.
Full changelog
Containarium v0.31.0
The open-source, self-hostable, agent-native sandbox.
What's new — experimental Kubernetes backend
Run an agent box as a pod in a Kubernetes cluster you already operate,
reached over SSH exactly like an LXC box — same in-the-box agent-box MCP
contract, no kube-apiserver token in the agent's hands. Each tenant gets a
namespace + StatefulSet pod under a restricted Pod Security policy and a
default-deny NetworkPolicy; SSH is fronted by an in-cluster sshpiper, with box
host keys pinned via known_hosts_data. client-go is isolated behind a k8s
build tag, so the default daemon is unchanged. End-to-end validated on
kind.
See the design doc:
docs/K8S-AGENT-BOX-RUNTIME-DESIGN.md
and the README section.
Binaries
Three binaries ship in this release:
| Binary | Where it runs | What it does |
|---|---|---|
| containarium | The host (and your laptop, for the CLI) | The platform daemon + CLI. create, list, expose-port, ssh-config, etc. |
| mcp-server | Your laptop | The platform MCP — outside-the-box admin (create_container, list_containers, expose_port, list_backends). Wire it into Claude Code / Cursor. |
| agent-box | Inside each Containarium container | The in-the-box MCP — shell_exec, read_file, write_file, etc. Reached over stdio, typically via SSH. |
Quick install (Linux host)
curl -fsSL https://raw.githubusercontent.com/footprintai/containarium/main/hacks/install.sh | sudo bash
Manual install (any binary, any platform)
# containarium CLI / daemon (Linux x86_64 example)
curl -L -o /usr/local/bin/containarium \
https://github.com/footprintai/containarium/releases/download/v0.31.0/containarium-linux-amd64
chmod +x /usr/local/bin/containarium
# Windows: client-only CLI (create/list/ssh/… against a remote daemon;
# the daemon/sentinel/tunnel subcommands are Linux/macOS only)
# PowerShell:
# curl.exe -L -o containarium.exe `
# https://github.com/footprintai/containarium/releases/download/v0.31.0/containarium-windows-amd64.exe
# platform MCP (your laptop, e.g. macOS arm64)
curl -L -o /usr/local/bin/mcp-server \
https://github.com/footprintai/containarium/releases/download/v0.31.0/mcp-server-darwin-arm64
chmod +x /usr/local/bin/mcp-server
# agent-box (drop into your container image, Linux x86_64)
curl -L -o /usr/local/bin/agent-box \
https://github.com/footprintai/containarium/releases/download/v0.31.0/agent-box-linux-amd64
chmod +x /usr/local/bin/agent-box
Verify checksums via SHA256SUMS.txt.
MCP client setup
Wire the platform MCP into Claude Code (~/.claude.json):
{
"mcpServers": {
"containarium": {
"command": "/usr/local/bin/mcp-server",
"env": {
"CONTAINARIUM_SERVER_URL": "http://your-host:8080",
"CONTAINARIUM_JWT_TOKEN": "<your-token>"
}
}
}
}
Wire agent-box for in-the-box file/shell ops:
{
"mcpServers": {
"containarium-box": {
"command": "ssh",
"args": ["user@your-box", "agent-box"]
}
}
}
See README.md for the full agent-native walkthrough.
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
About Containarium
All releases →Related context
Related tools
Beta — feedback welcome: [email protected]