5x faster Edge Functions: V8 isolates to Firecracker MicroVMs
Thread
Unofficial Hacker News client; not affiliated with Y Combinator.
5x faster Edge Functions: V8 isolates to Firecracker MicroVMs
Unofficial Hacker News client; not affiliated with Y Combinator.
Normal_gaussian · · focus · HN ↗
Honestly, while I see firecracker replacing docker on the horizon I don't see firecracker replacing v8 isolates for most edge function execution. Firstly, this article's scenario is a bit unusual in that they were using someone else's isolates - so adding on a few hops; secondly isolates running JS/TS can be statically analyzed quite well, and at scale looking historically for issues and exploits, in many edge compute scenarios this is quite desirable. MicroVMs can have an awful lot more flexibility so to get the same benefit you have to really lock down what is available - the trade-offs for mid-size companies seems to benefit isolates. Obviously netlify is more than big enough and relies heavily on this that it leans in their favour.
jst1fthsdys · · focus · HN ↗
binsquare · · focus · HN ↗
Fwiw, you can run this instead free and open source: <a href="https://github.com/smol-machines/smolvm" rel="nofollow">https://github.com/smol-machines/smolvm
Disclaimer: Am author.
QGQBGdeZREunxLe · · focus · HN ↗
Cyph0n · · focus · HN ↗
chrisweekly · · focus · HN ↗
binsquare · · focus · HN ↗
dprkh · · focus · HN ↗
binsquare · · focus · HN ↗
Functionality of criu built in so you can get rewind, pause, in an accessible manner.
Embeddable (you can write JavaScript to programmatically use an isolated environment)
Native performance on multiplatform + consistent experience across platforms.
stavros · · focus · HN ↗
EDIT: Ah, looks like it means "runs its own kernel", not "isolates at the kernel" like Docker does.
binsquare · · focus · HN ↗
containers are built on linux primitives & so shares the kernel.
stavros · · focus · HN ↗
zmmmmm · · focus · HN ↗
any point of comparison with microsandbox? [0]
[0] <a href="https://github.com/superradcompany/microsandbox" rel="nofollow">https://github.com/superradcompany/microsandbox
binsquare · · focus · HN ↗
Good sandboxing is a feature of a good VM.
Outside of that I support GPU and enables something called branchable computing.
Normal_gaussian · · focus · HN ↗
<a href="https://github.com/libkrun/libkrun" rel="nofollow">https://github.com/libkrun/libkrun
binsquare · · focus · HN ↗
Firecracker has a long track record but has a lot of knobs and tunings to get the security right.
smolvm's serve mode confines each VMM by default with a seccomp allowlist, Landlock, a per-VM uid and no_new_privs, much like Firecracker's jailer.
For dangerous workloads, people can do the same things such as skip host mounts and use virtio-net.
It's not a different security class just because it's libkrun vs firecracker
tomjen3 · · focus · HN ↗
binsquare · · focus · HN ↗
QGQBGdeZREunxLe · · focus · HN ↗
alexellisuk · · focus · HN ↗
Also: it has to be free.
So yes you're right, people confuse VC backed companies, and vibe-coded pet-projects for sustainable software.
SlicerVM was started in 2022 and internal only, plenty of YouTube videos and such about it - written completely manually from our Actuated work.
There's a free trial for anyone who wants to play about on their Mac or Linux computer, the comment here is from a real user (unprompted) that knew and used free alternatives previously.