Kuasar: An efficient multi-sandbox container runtime
github.com
github.com
Interestingly had a bunch of different Sandboxerd within. Wasm, microvm with common best-in-class tech (Firecracker, Cloud Hypervisor, qemu), & full KVM for unikernel systems (specifically atm a project Quark). runC is shown but not listed as an implementation. I had kind of thought this was specifically for Rust payloads but they just means written in Rust.
I am a bit surprised to hear the wasm model is forking. This system definitely values security & manageability so it shouldn't be surprising I guess. But it still feels like it might entail more loading & re-loading code to spawn than what I think of as wasm's strong point, where a new isolate can be created from a snapshot easily. Maybe the wasm runtime is more primed before forking than i realize, but the way they talk about forking then creating a runtime makes me think this isn't targeting lots of shortived instances.
Performance is exceedingly good versus the industry standard & very well tuned Kata Containers. 360ms Vs 850ms boot. Even better in parallel boots. Huge wins on memory overhead since there's a single manager process instead of per instance shims.
Neat project. I hope we see more of this & others. I'm curious who the team is & what else they are up to. Whoa... Huawei, Agricultural Bank of China, OpenEuler, are among the top listed users.
I'm also glad that the framework is open, allowing for engagement with various sandbox technologies. Additionally, the removal of the pause container is a significant improvement. Cheers!
It's fascinating to see how the shim process has evolved over time with the container form, from one container corresponding to one shim, to one Pod corresponding to one shim, and now to Kuasar's innovative proposal of one type of Pod corresponding to one sandboxer process, meaning N pods corresponding to one process. The evolution of the model has reduced the number of processes to only one, which has consequently reduced the memory consumption and helped with startup time.
Overall, I find this project to be quite exciting, and I'm hoping that the model put forward by Kuasar can be widely adopted and applied in production.