HNHacker News
TopNewBestAskShowJobs

5x faster Edge Functions: V8 isolates to Firecracker MicroVMs

netlify.com

81 points·jbott··29 comments
Open articleView on HN
Alex from Unikraft here! Happy to answer any questions about the microVM part of the story from our side.

We also did a couple of technical write ups if you're interested:

- https://unikraft.com/blog/netlify-edge-functions

- https://unikraft.com/customer-stories/edge-functions-netlify

I'm having trouble understanding/believing this, given that Cloudflare Workers are also v8 isolates and run vastly faster than the 25-40ms that netlify says their isolates took...
from the article: "With our old infrastructure it went out over the internet, ran the edge function, and came back to us to pass on. With the new compute platform, the request is forwarded to a compute node within our network."

As far as I know, Cloudflare Workers have always executed within Cloudflare's network, not gone out to the internet and executed elsewhere (which I read as being in a hyperscaler cloud).

> In the past, requests went out to a hosted execution service. Today, they run on MicroVMs inside our own edge network

The isolates were not being run at the edge.

They were running on the edge, and in the same datacenters but by another provider.
This is highly interesting considering AWS invented the MicroVMs for lambda, yet node on lambda is dog slow (both in latency and throughput). I can traumadump on request. I bet they could use some of this tech especially since their use cases are often not too dissimilar (auth validation, rule checking etc)
Wish it explained where the v8 isolate latency is coming from compared to microvms
v8 isolates aren't actually a great sandbox and I would not trust them implicitly in the AI era. This is probably why they wrap them in an additional sandbox.
Why are v8 isolates bad, I see speculative execution hacks, but are there others?
v8 isolates are still shared kernel

while microvm's are separate kernel + hardware virtualization through hypervisor guarantees

I wouldn't call it bad either, just different tools for different things

Despite naming them isolates, the V8 team does not consider them to be a security boundary.
The v8 JIT is very complex and can lead to sandbox escapes if there are type confusion bugs.
But I guess they are good enough to isolate multiple instances of the same code, ran by the same customer in parallel.
"In the past, requests went out to a hosted execution service."

They were outsourcing to another company so there's plenty of room for overhead to creep in.

If you're counting milliseconds why use Javascript?
V8 is extremely optimized for script startup time.
V8 isn't written in JavaScript?

Reply on news.ycombinator.com