AWS Firecracker Open Source: Secure and Fast MicroVM for Serverless Computing
aws.amazon.com
aws.amazon.com
sudo chmod 777 /dev/kvm
But... but... almost.The post was updated within 16 hours from the original post date.
Restricting /dev/kvm these days doesn't make much sense. The interface is designed to be safe for any user. The fact that we started as a character device and not syscalls is just a historical decision.
Since only the Firecracker user needs read/write access, it would be trivial to limit that to just the Firecracker user or group.
Step one, here is a guide that effectively removes all protections on the host system.
Win.