5x faster Edge Functions: V8 isolates to Firecracker MicroVMs
Thread
Unofficial Hacker News client; not affiliated with Y Combinator.
5x faster Edge Functions: V8 isolates to Firecracker MicroVMs
Unofficial Hacker News client; not affiliated with Y Combinator.
Normal_gaussian · · focus · HN ↗
Honestly, while I see firecracker replacing docker on the horizon I don't see firecracker replacing v8 isolates for most edge function execution. Firstly, this article's scenario is a bit unusual in that they were using someone else's isolates - so adding on a few hops; secondly isolates running JS/TS can be statically analyzed quite well, and at scale looking historically for issues and exploits, in many edge compute scenarios this is quite desirable. MicroVMs can have an awful lot more flexibility so to get the same benefit you have to really lock down what is available - the trade-offs for mid-size companies seems to benefit isolates. Obviously netlify is more than big enough and relies heavily on this that it leans in their favour.
dwroberts · · focus · HN ↗
I don’t think this is going to happen because they serve different purposes. Having to boot an entire OS inside a VM is a step backwards compared to containerisation. There are definitely use cases for isolating containers by running them inside a VM (see: Kata) but it generally ‘replacing’ docker, I don’t think that is on the horizon at all
(Also: you need KVM available, you need a rootfs to boot which will be larger than a container, it has no built in support for mounts or really any kind of communication with the host unless you explicitly set up networking etc for it)
spwa4 · · focus · HN ↗
If it boots faster than a container ...
Also containers don't work well with remote filesystems, or filesystems in general, because the admin always limits you.