5x faster Edge Functions: V8 isolates to Firecracker MicroVMs
Thread
Loading the complete thread in the background. This saved snapshot is available now. Refresh
Unofficial Hacker News client; not affiliated with Y Combinator.
5x faster Edge Functions: V8 isolates to Firecracker MicroVMs
Loading the complete thread in the background. This saved snapshot is available now. Refresh
Unofficial Hacker News client; not affiliated with Y Combinator.
TaupeRanger · · focus · HN ↗
CharlesW · · focus · HN ↗
aaronvg · · focus · HN ↗
vmg12 · · focus · HN ↗
dummydummy1234 · · focus · HN ↗
binsquare · · focus · HN ↗
while microvm's are separate kernel + hardware virtualization through hypervisor guarantees
I wouldn't call it bad either, just different tools for different things
londons_explore · · focus · HN ↗
I bet there are a million ways to cause side channels allowing learning about other code or data on the same machine, and just one V8 bug (of which there have historically been thousands) let's you take over or modify code in another isolate.
tbrockman · · focus · HN ↗
I don't think their model is "run everything in V8 isolates as the only isolation primitive", I believe it's closer to "run things with V8 isolates as the floor, dynamically trading efficiency for security in response to runtime (and I'd also assume static) analysis". They also add restrictions to make it more difficult/expensive for code to exploit side-channels (ex. changing the resolution and behavior of `performance.now ` and `Date.now` , no multithreading, no SharedArrayBuffer , etc.). Code attempting to exploit side-channels usually has a fingerprint. If you can classify it well enough, and the cost of a false positive is paying for the process isolation you'd otherwise have paid for everything all the time, you probably end up with healthier margins.
I don't disagree that there are real issues, but I don't think that Cloudflare necessarily misrepresents them (though they do perhaps fall quite a bit short of saying "don't run security critical workloads on our platform"). If you can accept the risk thought, you get cheap compute with someone else managing all the infrastructure. If you can't, you probably shouldn't be using Workers (and maybe not even cloud compute in general).
Sources:
* <a href="https://gruss.cc/files/scalableisolation.pdf" rel="nofollow">https://gruss.cc/files/scalableisolation.pdf
* <a href="https://arxiv.org/html/2110.04751v1" rel="nofollow">https://arxiv.org/html/2110.04751v1
* <a href="https://arxiv.org/pdf/2608.17043" rel="nofollow">https://arxiv.org/pdf/2608.17043
* <a href="https://blog.cloudflare.com/revisiting-spectre-attacks-on-workers/" rel="nofollow">https://blog.cloudflare.com/revisiting-spectre-attacks-on-wo...
kentonv · · focus · HN ↗
At some point you have to decide where along the spectrum you want to put the boundary of "acceptable" for your workload.
Some people argue that isolates are below the necessary threshold and micro VMs are above it. But this isn't really based on any rigorous mathematical analysis, it's mostly vibes. It used to be that people said VMs weren't secure enough for critical workloads, but few people say that these days.
I would argue that we (Cloudflare) have demonstrated that the isolate model can work fine if done carefully: we've been doing it this way for nearly a decade with no breaches.
* Not "strictly riskier", though. There are some risks micro VMs have that V8 isolates do not. Micro VMs that allow tenants to run arbitrary x86 code place a huge amount of trust in the hardware to be exactly correct; a trusted JIT makes it much easier to work around hardware bugs when they are found.
vmg12 · · focus · HN ↗
I think as a general rule you'd just want multiple uncorrelated layers of isolation. If you aren't willing to spend what cf does on securing v8 isolates I think process isolation + seccomp + v8 isolates might be enough, otherwise all of our browsers would be ticking time bombs.
tbrockman · · focus · HN ↗
phickey · · focus · HN ↗
vmg12 · · focus · HN ↗
torginus · · focus · HN ↗
Normal_gaussian · · focus · HN ↗
torginus · · focus · HN ↗
wmf · · focus · HN ↗
They were outsourcing to another company so there's plenty of room for overhead to creep in.
nchmy · · focus · HN ↗
phickey · · focus · HN ↗
As far as I know, Cloudflare Workers have always executed within Cloudflare's network, not gone out to the internet and executed elsewhere (which I read as being in a hyperscaler cloud).
nchmy · · focus · HN ↗
Perhaps the article says that, but the framing is all wrong
irq-1 · · focus · HN ↗
The isolates were not being run at the edge.
bobfunk · · focus · HN ↗
ascorbic · · focus · HN ↗
secondcoming · · focus · HN ↗
wmf · · focus · HN ↗
pjmlp · · focus · HN ↗
nkmnz · · focus · HN ↗
chrisweekly · · focus · HN ↗
pjmlp · · focus · HN ↗
nderjung · · focus · HN ↗
We also did a couple of technical write ups if you're interested:
- <a href="https://unikraft.com/blog/netlify-edge-functions" rel="nofollow">https://unikraft.com/blog/netlify-edge-functions
- <a href="https://unikraft.com/customer-stories/edge-functions-netlify" rel="nofollow">https://unikraft.com/customer-stories/edge-functions-netlify
anentropic · · focus · HN ↗
I guess I am curious if/how exactly the Netlify announcement relates to unikernels?
torginus · · focus · HN ↗
tomnipotent · · focus · HN ↗
Firecracker is AWS tech, and is behind both Lambda & Fargate.
nderjung · · focus · HN ↗
<a href="https://unikraft.com/blog/unikraft-vs-firecracker" rel="nofollow">https://unikraft.com/blog/unikraft-vs-firecracker
tomnipotent · · focus · HN ↗
fragmede · · focus · HN ↗
tomnipotent · · focus · HN ↗
fragmede · · focus · HN ↗
tomnipotent · · focus · HN ↗
fragmede · · focus · HN ↗
tomnipotent · · focus · HN ↗
fragmede · · focus · HN ↗
pjmlp · · focus · HN ↗
ascorbic · · focus · HN ↗
nderjung · · focus · HN ↗
0xCMP · · focus · HN ↗
zokier · · focus · HN ↗
binsquare · · focus · HN ↗
as someone who worked on it
tomnipotent · · focus · HN ↗
<a href="https://github.com/firecracker-microvm/firecracker" rel="nofollow">https://github.com/firecracker-microvm/firecracker
"Firecracker was developed at Amazon Web Services to accelerate the speed and efficiency of services like AWS Lambda and AWS Fargate."
notatoad · · focus · HN ↗
chrisweekly · · focus · HN ↗
notatoad · · focus · HN ↗
chrisweekly · · focus · HN ↗
momojo · · focus · HN ↗
jedberg · · focus · HN ↗
Onavo · · focus · HN ↗
When MBA (and YC startup) schools teach to build product with a "high switching cost", they do not have consumer's (in this case the developers) interests in mind.
The other issue is that outside of the core offerings (S3, EC2/Lambdas, the logging and queuing services), everything else seems to be in a perpetual state of beta with products shipped by interns. The situation is not as bad as Cloudflare but the bar's on the ground. Pre-LLM, services like Cognito caused developers no end of pain and suffering. Poor documentation, buggy products opaque console UIs, there's no end to complaints when it comes to AWS. If their services were designed well, then companies like Vercel and Heroku shouldn't exist at all.
And what's worse, with all of their efforts at squeezing customers, they still pay the worst of out of all of the big techs for non-senior leadership day to day engineering ICs. At least with Facebook there's commensurate pay. It's like Amazon took a look at Asian "996" culture and figured that if it works for their warehouse staff it should be good for the engineering folks too.
gottorf · · focus · HN ↗
Crazy that Heroku with its head start has become abandonware. Goes to show that no incumbent is immune to change.
fragmede · · focus · HN ↗
nitwit005 · · focus · HN ↗
Normal_gaussian · · focus · HN ↗
Honestly, while I see firecracker replacing docker on the horizon I don't see firecracker replacing v8 isolates for most edge function execution. Firstly, this article's scenario is a bit unusual in that they were using someone else's isolates - so adding on a few hops; secondly isolates running JS/TS can be statically analyzed quite well, and at scale looking historically for issues and exploits, in many edge compute scenarios this is quite desirable. MicroVMs can have an awful lot more flexibility so to get the same benefit you have to really lock down what is available - the trade-offs for mid-size companies seems to benefit isolates. Obviously netlify is more than big enough and relies heavily on this that it leans in their favour.
jst1fthsdys · · focus · HN ↗
binsquare · · focus · HN ↗
Fwiw, you can run this instead free and open source: <a href="https://github.com/smol-machines/smolvm" rel="nofollow">https://github.com/smol-machines/smolvm
Disclaimer: Am author.
QGQBGdeZREunxLe · · focus · HN ↗
Cyph0n · · focus · HN ↗
chrisweekly · · focus · HN ↗
binsquare · · focus · HN ↗
dprkh · · focus · HN ↗
binsquare · · focus · HN ↗
Functionality of criu built in so you can get rewind, pause, in an accessible manner.
Embeddable (you can write JavaScript to programmatically use an isolated environment)
Native performance on multiplatform + consistent experience across platforms.
stavros · · focus · HN ↗
binsquare · · focus · HN ↗
containers are built on linux primitives & so shares the kernel.
stavros · · focus · HN ↗
zmmmmm · · focus · HN ↗
any point of comparison with microsandbox? [0]
[0] <a href="https://github.com/superradcompany/microsandbox" rel="nofollow">https://github.com/superradcompany/microsandbox
binsquare · · focus · HN ↗
Good sandboxing is a feature of a good VM.
Outside of that I support GPU and enables something called branchable computing.
Normal_gaussian · · focus · HN ↗
<a href="https://github.com/libkrun/libkrun" rel="nofollow">https://github.com/libkrun/libkrun
binsquare · · focus · HN ↗
Firecracker has a long track record but has a lot of knobs and tunings to get the security right.
smolvm's serve mode confines each VMM by default with a seccomp allowlist, Landlock, a per-VM uid and no_new_privs, much like Firecracker's jailer.
For dangerous workloads, people can do the same things such as skip host mounts and use virtio-net.
It's not a different security class just because it's libkrun vs firecracker
tomjen3 · · focus · HN ↗
binsquare · · focus · HN ↗
QGQBGdeZREunxLe · · focus · HN ↗
alexellisuk · · focus · HN ↗
Also: it has to be free.
So yes you're right, people confuse VC backed companies, and vibe-coded pet-projects for sustainable software.
SlicerVM was started in 2022 and internal only, plenty of YouTube videos and such about it - written completely manually from our Actuated work.
There's a free trial for anyone who wants to play about on their Mac or Linux computer, the comment here is from a real user (unprompted) that knew and used free alternatives previously.
innocent_name · · focus · HN ↗
dwroberts · · focus · HN ↗
I don’t think this is going to happen because they serve different purposes. Having to boot an entire OS inside a VM is a step _backwards_ compared to containerisation. There are definitely use cases for isolating containers by running them inside a VM (see: KubeVirt) but it generally ‘replacing’ docker, I don’t think that is on the horizon at all
(Also: you need KVM available, you need a rootfs to boot which will be larger than a container, it has no built in support for mounts or really any kind of communication with the host unless you explicitly set up networking etc for it)
jeroenhd · · focus · HN ↗
The whole point of Firecracker over normal VM solutions is that "booting an OS" takes milliseconds.
Still, I don't think Docker is at risk of being replaced just yet because of the resource management benefits you get from sharing a kernel.
Normal_gaussian · · focus · HN ↗
There's definitely a tradeoff, but IME it's not as drastic as you first think.
dwroberts · · focus · HN ↗
troupo · · focus · HN ↗
Define "OS". A barebones OS will indeed start in microseconds. But then your app/service won't. Because it will likely need a gazillion things that a barebones OS doesn't provide. Suddenly the startup time isn't microseconds or even milliseconds.
Sadly, we never got the promise of unikernels, and everything requires the full-blown OS to run anything
jeroenhd · · focus · HN ↗
I don't have any recent measurements myself, but the startup time for a full Linux kernel using Firecracker's snapshotting feature seems to be around 30ms if you optimise calls for latency: <a href="https://dev.to/adwitiya/how-i-built-sandboxes-that-boot-in-28ms-using-firecracker-snapshots-i0k" rel="nofollow">https://dev.to/adwitiya/how-i-built-sandboxes-that-boot-in-2...
The measurements in that blog post place Firecracker above Docker in terms of startup performance. Most of that delay is probably the Docker daemon rather than Linux namespace APIs, but that's beside the point.
Huggingface places Firecracker startup time between 100-300ms while Docker is at 50-200ms, based on Kata: <a href="https://huggingface.co/blog/agentbox-master/firecracker-vs-docker-tech-boundary" rel="nofollow">https://huggingface.co/blog/agentbox-master/firecracker-vs-d...
Either way, latency is in the same ballpark of "low enough that it only matters in edge cases".
pjmlp · · focus · HN ↗
The gazillion things that the OS doesn't provide is taken care by language runtimes, which can perfectly run directly on top of type 1 hypervisors.
In similar way how some of those languages have bare metal implementations for embedded development, where the runtime takes the OS role.
Naturally on languages with things runtimes and heavy reliance on POSIX like C and C++, this isn't as straightforward.
chrisweekly · · focus · HN ↗
These days I'm looking at microvms (esp. smolvm from smolmachines.com) by default, for anything where I'd previously have reached for docker (via colima or more recently orbstack).
spwa4 · · focus · HN ↗
If it boots faster than a container ...
Also containers don't work well with remote filesystems, or filesystems in general, because the admin always limits you.
tietjens · · focus · HN ↗
CodesInChaos · · focus · HN ↗
That sounds scary, since forked RNG states can lead to catastrophic failures in UUID generators or cryptography.
ameliaquining · · focus · HN ↗
tybit · · focus · HN ↗
CodesInChaos · · focus · HN ↗
[deleted] · · focus · HN ↗
[deleted]
[deleted] · · focus · HN ↗
[deleted]
yencabulator · · focus · HN ↗
ContinuityLab · · focus · HN ↗
[dead]
groundzeros2015 · · focus · HN ↗
WatchDog · · focus · HN ↗
As they mention, the v8 latency was because the v8 runtime was hosted externally.
Firecracker has better security model.
This old thread[0] with kentonv author of Cloudflare's workers platform covers some of the differences.
[0]: <a href="https://news.ycombinator.com/item?id=31740885">https://news.ycombinator.com/item?id=31740885
tinykit · · focus · HN ↗
[dead]
sorenbs · · focus · HN ↗
ur-whale · · focus · HN ↗
Off-topic, but ...
I've noticed over the last 5 years I find myself increasingly incapable of understanding the title of HN posts. The likely explanation is that I'm probably getting old and senile, but maybe, maybe, I am not the only one.
This post's title is a decent example, albeit far from the worse I've read.
I think HN should have a feature to graph the level of incomprehensibility of post titles over time.
An LLM should probably be able to measure this automatically.
masklinn · · focus · HN ↗
Here it looks like you haven’t gotten interested or kept up with some of the field, none of “edge functions”, “v8 isolates”, and “microvms” / “firecracker microvms” are ultra novel or made up, just relatively specialised.
franciscop · · focus · HN ↗
The idea behind Fetchable is to have a (semi) standard across runtimes and environments to be able to do this:
Even Node.js, who are traditionally the laggards in these things, are already working on it and implementing it. This would be very useful for library writers like me to be able to standardize code across envrionments. I'm re-writing npm's `server` (currently WIP here [3]) and I have some ugly workarounds ONLY for Netlify Edge Functions.[1] <a href="https://fetchable.org/" rel="nofollow">https://fetchable.org/ [2] <a href="https://answers.netlify.com/t/support-fetch-for-netlify-edge-functions/170521" rel="nofollow">https://answers.netlify.com/t/support-fetch-for-netlify-edge... [3] <a href="https://server-js.com/" rel="nofollow">https://server-js.com/
pjmlp · · focus · HN ↗
mb2100 · · focus · HN ↗
franciscop · · focus · HN ↗
pjmlp · · focus · HN ↗
dantesays · · focus · HN ↗
[dead]
vivzkestrel · · focus · HN ↗
- i want to run untrusted user submitted code (any programming language literally, no exceptions)
- my setup is running on aws
- a new sandbox comes up every week
- we got E2B, Modal, daytona, Docker sandbox, I could probably name a 100 more
- what is the cheapest and fastest way to do this? ( i would prefer being inside AWS)
flybayer · · focus · HN ↗