1,064 karma · joined October 1, 2019
I focus on being the batteries-included approach for microVMs. So network is off by default, and you can allow specific hosts (DNS is filtered too), so an agent can reach its model API and nothing else.
And then I also put a lot of work in the jailer-style hardening around the VMM process itself: seccomp allowlist, Landlock, separate unprivileged uid per VM, and cgroup limits.
So that users have security & knobs right out of the box.
fwiw i used to operate an AWS service using firecracker.
Because the current needs are extremely lightweight and isolated environments i.e. vm per workload rather than shared.
And there's been a lot of wonderful innovations happen there
Even the same old games are still there
Firecracker has a long track record but has a lot of knobs and tunings to get the security right.
smolvm's serve mode confines each VMM by default with a seccomp allowlist, Landlock, a per-VM uid and no_new_privs, much like Firecracker's jailer.
For dangerous workloads, people can do the same things such as skip host mounts and use virtio-net.
It's not a different security class just because it's libkrun vs firecracker
containers are built on linux primitives & so shares the kernel.
Good sandboxing is a feature of a good VM.
Outside of that I support GPU and enables something called branchable computing.
Functionality of criu built in so you can get rewind, pause, in an accessible manner.
Embeddable (you can write JavaScript to programmatically use an isolated environment)
Native performance on multiplatform + consistent experience across platforms.
as someone who worked on it
Fwiw, you can run this instead free and open source: https://github.com/smol-machines/smolvm
Disclaimer: Am author.
while microvm's are separate kernel + hardware virtualization through hypervisor guarantees
I wouldn't call it bad either, just different tools for different things
Agentic workloads are trained and largely based on human workloads. Albeit properties and scale can be different.
A concrete example might be helpful to me because I don't understand the binary conclusion
Think it's a good match
Every cloud provider dealt with it and concluded that virtual machine technology is an important part of that stack.
Couple it with the right observability, tooling I do think we can curb risks posed by agents.
Performance doesn't have to be supbar, infact with the right properties and focus on being lightweight - I see 90% of native performance.
I work on this as context: https://github.com/smol-machines/smolvm
Those who are above the bar can steer and add their expertise to hit a new level.
It's an idea I had to basically makes it possible to checkpoint, branch, rollback the entire vm kind of like git but on the entire computer.