For the most part, Amazon EC2 is excluded from firecracker, unless you pay at the top end for bare metal EC2 instances.
Odd.
For the most part, Amazon EC2 is excluded from firecracker, unless you pay at the top end for bare metal EC2 instances.
Odd.
Can you reference anything tangible to say that nested virtualization is too buggy to use in production?
"While Red Hat is now doing some level of QA for cascaded KVM, we are not supporting it - so it is clearly not meant for production use."
https://www.linux-kvm.org/page/Nested_Guests
"As of Feb 2018 this feature is considered working but experimental, and some limitations apply."
https://www.phoronix.com/scan.php?page=news_item&px=KVM-Linu...
It looks like xen has spotty support[3] as well. Amazon uses a heavily forked version of xen, so I suspect support for it is even worse on their version.
(EDIT: added info on xen)
[1]: https://www.redhat.com/en/blog/inception-how-usable-are-nest...
[2]: https://bugs.launchpad.net/qemu/+bug/1661386
[3]: https://wiki.xenproject.org/wiki/Nested_Virtualization_in_Xe...
Edit: If you do want to try testing nested KVM, then try my supernested project: http://git.annexia.org/?p=supernested.git;a=summary and Day 13 of the 2016 QEMU Advent Calendar https://www.qemu-advent-calendar.org/2016/
Edit 2: Don't confused nested KVM with nesting TCG. That's fine, albeit rather slow.
Prove it and you'll get a bug bounty from Doogle and Microsoft won't you?
I always assumed that the reason it was disabled had something to do with nested virtualization being less mature in xen-hvm than in kvm. I don't know if it is actually less mature in xen-hvm, but all of the other cloud providers are using other hypervisors so I figured xen-hvm was relevant. That said, Amazon has now released the m5, c5, etc instance types which run on kvm, but nested virtualization is still not supported.
Regardless of stability and performance, it's frustrating that they outright disable nested virtualization because it is useful in so many cases that aren't performance-critical where you really need to just run a VM: like building virtual machine images, adding another layer of isolation for untrusted software, or working with applications that cause kernel bugs (chromedriver a few years back was plaguing us with system deadlocks running at scale), etc.