Firecracker MicroVMs
firecracker-microvm.github.io
firecracker-microvm.github.io
- https://github.com/buildbuddy-io/buildbuddy/blob/master/ente...
This might be related to my network problem, I will try other deploy ways when I get some spare time.
“If a story has not had significant attention in the last year or so, a small number of reposts is ok. Otherwise we bury reposts as duplicates.”
Like for example if fly.io was announced yesterday, and they said they used Firecracker, then someone would submit this link about Firecracker.
So the original poster in this thread was wondering if there was something to that effect. Not decrying something being posted that was not new or already discussed before...
assume that the parent's not saying "you shouldn't have posted this, it's old", but rather "i'm interested in firecracker, was there some new development i missed that prompted this submission"... if the answer is no that's okay, but if the answer is yes i'd love to hear about it.
Firecracker: Secure and fast microVMs for serverless computing - https://news.ycombinator.com/item?id=22512196 - March 2020 (103 comments)
OpenWrt's build system has a method of building rootfs ext4 and squashfs images without any root, it's somewhere in that large Makefile mess.
(sorry, reposting this as I first replied to the wrong parent)
And yes, I've studied the OpenWRT build to no avail. I would be delighted for someone to dissect whatever it is that goes on in there and write it up.
sudo $GOPATH/bin/firebuild rootfs \
--profile=standard \
--dockerfile=git+https://github.com/hashicorp/docker-consul.git:/0.X/Dockerfile \
--cni-network-name=machine-builds \
--ssh-user=alpine \
--vmlinux-id=vmlinux-v5.8 \
--tag=combust-labs/consul:1.9.4
That SSH bit is no longer required as I'm using MMDS instead.Thanks for these write-ups. They make for a riveting read, even when more than half of it usually is beyond my technical know-how.
[1] https://aws.amazon.com/blogs/opensource/kata-containers-1-5-...
[2] https://github.com/kata-containers/kata-containers/blob/main...
https://github.com/firecracker-microvm/firecracker-container...
This repository enables the use of a container runtime, containerd, to manage Firecracker microVMs. Like traditional containers, Firecracker microVMs offer fast start-up and shut-down and minimal overhead. Unlike traditional containers, however, they can provide an additional layer of isolation via the KVM hypervisor.
And of course AWS Fargate and Lambda use this tech under the hood transparently, so that's always an option if you don't want to host and operate it yourself.
https://www.nomadproject.io/docs/drivers/external/firecracke...
Or am I too paranoid about container escapes?
The malicious person can always find the worst way to break everything, but dumb luck can get you pretty close.
It does however work on Google, Azure and Digital Ocean instances where you can configure nested virtualisation.
That is definitely a constraint though, as the smallest available metal instances are pretty large, hence costly on a per instance basis.
Why not? And what is Google, Azure and DI doing differently
That said, it works fine on EC2 Bare Metal instances.
(n.b., I work on the virtualization stack on Google Compute Engine)
@bushbaba I wonder how large the percentage hit could be, if it's like 1% or 10%, if you happen to know
And how that percentage hit compares with gvisor performance wise