- 40ms for nsjail run an isolated command and exit [1]
- 150[2]-250ms to boot a firecracker microvm
- ~450ms for docker startup [3]
There are probably very good reasons for the difference (e.g. docker has layered filesystems to set up), but the default experience makes a difference.
[0] https://news.ycombinator.com/item?id=24853660
[1] `nsjail --user 9999 --group 9999 -macvlan_iface wlp2s0 --chroot / -Mo --macvlan_vs_ip 192.168.0.44 --macvlan_vs_nm 255.255.255.0 --macvlan_vs_gw 192.168.0.1 -- /bin/true`
[2] https://blog.acolyer.org/2020/03/02/firecracker/
[3] `docker run -d ubuntu:18.04 true`
However, in this context (being on a rpi) it probably wouldn't be the case.
Now, as for the firecracker discussion: Firecracker trades a faster boot time for a slower runtime as evidenced by this issue here:
https://github.com/nanovms/nanos/issues/483#issuecomment-650...
There are plans to fix this but afaict this is the case today.