They were outsourcing to another company so there's plenty of room for overhead to creep in.
while microvm's are separate kernel + hardware virtualization through hypervisor guarantees
I wouldn't call it bad either, just different tools for different things
I bet there are a million ways to cause side channels allowing learning about other code or data on the same machine, and just one V8 bug (of which there have historically been thousands) let's you take over or modify code in another isolate.
I don't think their model is "run everything in V8 isolates as the only isolation primitive", I believe it's closer to "run things with V8 isolates as the floor, dynamically trading efficiency for security in response to runtime (and I'd also assume static) analysis". They also add restrictions to make it more difficult/expensive for code to exploit side-channels (ex. changing the resolution and behavior of `performance.now ` and `Date.now` , no multithreading, no SharedArrayBuffer , etc.). Code attempting to exploit side-channels usually has a fingerprint. If you can classify it well enough, and the cost of a false positive is paying for the process isolation you'd otherwise have paid for everything all the time, you probably end up with healthier margins.
I don't disagree that there are real issues, but I don't think that Cloudflare necessarily misrepresents them (though they do perhaps fall quite a bit short of saying "don't run security critical workloads on our platform"). If you can accept the risk though, you get cheap compute with someone else managing all the infrastructure. If you can't, you probably shouldn't be using Workers (and maybe not even cloud compute in general).
Sources:
* https://gruss.cc/files/scalableisolation.pdf
* https://arxiv.org/html/2110.04751v1
* https://arxiv.org/pdf/2608.17043
* https://blog.cloudflare.com/revisiting-spectre-attacks-on-wo...
At some point you have to decide where along the spectrum you want to put the boundary of "acceptable" for your workload.
Some people argue that isolates are below the necessary threshold and micro VMs are above it. But this isn't really based on any rigorous mathematical analysis, it's mostly vibes. It used to be that people said VMs weren't secure enough for critical workloads, but few people say that these days.
I would argue that we (Cloudflare) have demonstrated that the isolate model can work fine if done carefully: we've been doing it this way for nearly a decade with no breaches.
* Not "strictly riskier", though. There are some risks micro VMs have that V8 isolates do not. Micro VMs that allow tenants to run arbitrary x86 code place a huge amount of trust in the hardware to be exactly correct; a trusted JIT makes it much easier to work around hardware bugs when they are found.
And I'd say this even is a majority use case.