New, secure, VM..
sudo chmod 777 /dev/kvm
But... but... almost. sudo chmod 777 /dev/kvm
But... but... almost.The post was updated within 16 hours from the original post date.
Since only the Firecracker user needs read/write access, it would be trivial to limit that to just the Firecracker user or group.
Step one, here is a guide that effectively removes all protections on the host system.
Win.
Restricting /dev/kvm these days doesn't make much sense. The interface is designed to be safe for any user. The fact that we started as a character device and not syscalls is just a historical decision.