Fwiw, you can run this instead free and open source: https://github.com/smol-machines/smolvm
Disclaimer: Am author.
Fwiw, you can run this instead free and open source: https://github.com/smol-machines/smolvm
Disclaimer: Am author.
Firecracker has a long track record but has a lot of knobs and tunings to get the security right.
smolvm's serve mode confines each VMM by default with a seccomp allowlist, Landlock, a per-VM uid and no_new_privs, much like Firecracker's jailer.
For dangerous workloads, people can do the same things such as skip host mounts and use virtio-net.
It's not a different security class just because it's libkrun vs firecracker
any point of comparison with microsandbox? [0]
Good sandboxing is a feature of a good VM.
Outside of that I support GPU and enables something called branchable computing.
Functionality of criu built in so you can get rewind, pause, in an accessible manner.
Embeddable (you can write JavaScript to programmatically use an isolated environment)
Native performance on multiplatform + consistent experience across platforms.
EDIT: Ah, looks like it means "runs its own kernel", not "isolates at the kernel" like Docker does.
containers are built on linux primitives & so shares the kernel.