Docker isolation does not eliminate the need for a model API key. DeepAgents needs a model provider for inference, while its backend determines where commands run and files are handled. The documented deepagents-docker setup uses an OpenAI model and API key; Docker’s separate local-model options apply to Docker Sandbox’s built-in agents, not a verified DeepAgents recipe.
What Docker does—and does not—replace
There are two separate components to configure:
- Model provider: generates the agent’s responses. A hosted provider typically requires credentials.
- Execution backend: handles commands and files used by the agent. A Docker backend runs command execution in a container.
Putting execution in a container can separate it from direct host command execution, but it does not move model inference off a hosted service or remove the credentials that service requires. The DeepAgents Docker package documentation demonstrates the distinction: it passes a Docker backend to the agent while selecting openai:gpt-5.5 as the model, and its prerequisites include an OpenAI API key.
Run the documented DeepAgents Docker setup
The package documentation provides a Docker-backed DeepAgents example, but that example is for a hosted OpenAI model, not a no-cloud-key configuration. The package page lists Python 3.12 or higher; check its current requirements and release details before installing, since package compatibility can change.
- Install Docker and meet the Python requirement. The package documentation lists Docker and Python 3.12 or higher as prerequisites.
- Install the package. Use
uv add deepagents-dockerorpip install deepagents-docker. - Provide the model credential. Configure the OpenAI API key in the environment used by the Python process, following the provider’s instructions.
- Create the agent with the Docker backend. The package’s documented pattern imports
DockerSandboxand passesbackend=DockerSandbox()tocreate_deep_agent, withmodel="openai:gpt-5.5"in its quickstart example.
For the package’s API and current configuration options, consult its repository documentation. It describes a long-running container for command execution. By default, the container is removed when the Python process exits; a context manager can be used for earlier cleanup.
Quick wins for a faster PC:
Scan for outdated or missing drivers - takes under a minuteDriver Scan →Repair Windows errors before they cause bigger problemsFix Now →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →#1 Best Overall
Choose where agent files live
If you set shared_dir, the selected host directory is mounted inside the container at /shared. If you omit it, the package creates a temporary host directory and removes it when the backend closes. Files placed in a shared directory are exposed to the agent, so do not put secrets there.
Set resource and runtime options deliberately
The package documents options for the container image, outbound traffic, timeout, memory, CPUs, PID limit, and additional Docker run flags. These configure the package’s container; their presence is not proof of a hardened security boundary.
Rank #2
What Docker’s local-model options actually support
Docker documents local models for its separate Docker Sandboxes sbx feature. That is useful evidence that Docker can connect its built-in sandbox agents to local inference, but the examples are for the built-in claude, codex, and opencode agents. They do not configure create_deep_agent or establish that DeepAgents works with those options.
Docker’s local and hosted models documentation describes local models managed by llmman, an existing Ollama installation, hosted providers, and configured endpoints. Model selection is marked experimental and requires enabling the relevant experimental settings.
Free tools Windows power users keep installed
One-click scans. No signup required.
Rank #3
Use a model managed by llmman
For Docker’s built-in sandbox agent flow, the docs show sbx run --model gemma4 to select a local llmman-managed model. This is not a DeepAgents command.
Connect Docker Sandbox to an existing Ollama service
For its built-in-agent flow, Docker documents sbx run --model gemma4 --provider ollama claude. Docker says the Ollama route connects to the host at localhost:11434; Docker does not install, start, or manage Ollama. The command should not be treated as a way to configure DeepAgents’ model provider.
Account for local inference resources
Docker states: “The model runs on the host, so its memory and compute requirements are separate from the sandbox’s resource limits.” In practice, container memory or CPU settings do not by themselves size or constrain the host resources needed by a local model. The cited Docker documentation does not specify hardware requirements for a particular model.
Can DeepAgents use Ollama without a cloud key?
The available documentation supports a plausible direction, but not a verified end-to-end recipe: LangChain describes Ollama as a way to run open models locally and provides a ChatOllama integration; the Deep Agents overview says the framework is model-provider agnostic. Those separate facts do not confirm that a particular DeepAgents version, ChatOllama, and deepagents-docker work together as configured.
Best Value
- Docker, Docker Swarm, Docker Compose, Programmer, Developer, Coding, Programming, Software Engineer, Code, DevOps, Deploy, Deployment, Kubernetes, Salt, Puppet, Chef, Terraform, Container, AWS, Azure, Cloud, Geek, Funny, Computer, Software, Tech, IT
- Integration, Scrum, Compile, Compilation, Science, Bug, Debug, Python, Linux, Java, Javascript, Scala, Dotnet, Kotlin
- Lightweight, Classic fit, Double-needle sleeve and bottom hem
Accordingly, do not assume that substituting an Ollama model name into the package’s hosted-model example will work. The exact DeepAgents–Ollama–Docker backend combination is not established by the cited setup documentation. Verify compatibility against the specific library versions and their current APIs before relying on it.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Choose an approach based on the no-key requirement
| Approach | Where inference runs | Cloud credential in documented flow? | DeepAgents integration evidence |
|---|---|---|---|
deepagents-docker quickstart |
Hosted OpenAI model | Yes; the example requires an OpenAI API key, according to the package documentation. | Documented DeepAgents Docker backend, but not a no-key setup. |
| Docker Sandbox with llmman local model | Local model managed by llmman | No hosted-provider credential in the documented local-model flow, according to Docker Docs. | Examples cover Docker’s built-in agents, not create_deep_agent. |
| Docker Sandbox with host Ollama | Ollama on the host, reached at localhost:11434 |
No hosted-provider credential in the documented Ollama flow, according to Docker Docs. | Examples cover Docker’s built-in agents, not the DeepAgents Docker package. |
| DeepAgents with Ollama and Docker backend | Would be local if configured to use local Ollama | Potentially no hosted-provider key, but the combined setup is not confirmed by the cited documentation. | Unverified combination; LangChain’s separate ChatOllama documentation and the Deep Agents overview do not establish it. |
Understand the isolation and data limits
A container is a boundary for command execution, not a promise that shared project data cannot be changed. Docker’s sandbox tutorial describes a private environment with its own operating system and Docker daemon, while noting that the project directory is shared read-write. An agent can therefore modify or delete project files visible on the host.
The DeepAgents LocalShellBackend is a different choice: its commands run directly on the host without sandboxing, process isolation, or security restrictions. The backend documentation warns that commands can access files available to the user, including credentials, and recommends an isolated backend such as Docker or a VM when isolation is required.
The deepagents-docker project advises using its package for trusted workloads and development rather than treating it as a hard multi-tenant security boundary. In particular, keep secrets out of the shared folder. A local model does not make unsafe tool access safe, and containerization alone does not establish that every path to host data is blocked.
Quick Recap
Practical decision
- If you need the documented DeepAgents Docker path now, use its hosted-model example and provide the required provider credential.
- If avoiding a hosted model key is the priority, Docker’s llmman and Ollama instructions describe local inference for Docker’s built-in agents, not DeepAgents.
- If you want DeepAgents with local Ollama, treat it as an integration to validate for your exact versions rather than a documented turnkey recipe.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




