‹ BackHN Continuity

Thread

5x faster Edge Functions: V8 isolates to Firecracker MicroVMs

229 points · 106 comments · jbott

  1. Normal_gaussian · · focus · HN ↗
    I've been using SlicerVM extensively - which is Firecracker MicroVMs for the regular person (and for the irregular with their platform offering) - to run local 'edge' style workloads locally and securly. Agents, local dev CI, etc. It slotted in and replaced my proxmox vm orchestrator, and now I have secure and and fast vms on my laptop wherever I go. It also supports dockerfile style builds if you're wanting a security upgrade from containers (which, you should if you're using agents).

    Honestly, while I see firecracker replacing docker on the horizon I don't see firecracker replacing v8 isolates for most edge function execution. Firstly, this article's scenario is a bit unusual in that they were using someone else's isolates - so adding on a few hops; secondly isolates running JS/TS can be statically analyzed quite well, and at scale looking historically for issues and exploits, in many edge compute scenarios this is quite desirable. MicroVMs can have an awful lot more flexibility so to get the same benefit you have to really lock down what is available - the trade-offs for mid-size companies seems to benefit isolates. Obviously netlify is more than big enough and relies heavily on this that it leans in their favour.

    1. jst1fthsdys · · focus · HN ↗
      25 USD/m to run a daemon on my own hardware. Yikes.
      1. binsquare · · focus · HN ↗
        That seems off to me as well.

        Fwiw, you can run this instead free and open source: <a href="https:&#x2F;&#x2F;github.com&#x2F;smol-machines&#x2F;smolvm" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;smol-machines&#x2F;smolvm

        Disclaimer: Am author.

        1. Normal_gaussian · · focus · HN ↗
          Smolvm with it&#x27;s libkrun vmm provides significantly worse security positioning than slicervms use of firecracker, which leads to slicervm for any dangerous or secure workload.

          <a href="https:&#x2F;&#x2F;github.com&#x2F;libkrun&#x2F;libkrun" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;libkrun&#x2F;libkrun

          1. binsquare · · focus · HN ↗
            Libkrun and firecracker had similar foundations (Rust, KVM, rust-vmm).

            Firecracker has a long track record but has a lot of knobs and tunings to get the security right.

            smolvm&#x27;s serve mode confines each VMM by default with a seccomp allowlist, Landlock, a per-VM uid and no_new_privs, much like Firecracker&#x27;s jailer.

            For dangerous workloads, people can do the same things such as skip host mounts and use virtio-net.

            It&#x27;s not a different security class just because it&#x27;s libkrun vs firecracker

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.