‹ BackHN Continuity

Thread

5x faster Edge Functions: V8 isolates to Firecracker MicroVMs

229 points · 106 comments · jbott

  1. Normal_gaussian · · focus · HN ↗
    I've been using SlicerVM extensively - which is Firecracker MicroVMs for the regular person (and for the irregular with their platform offering) - to run local 'edge' style workloads locally and securly. Agents, local dev CI, etc. It slotted in and replaced my proxmox vm orchestrator, and now I have secure and and fast vms on my laptop wherever I go. It also supports dockerfile style builds if you're wanting a security upgrade from containers (which, you should if you're using agents).

    Honestly, while I see firecracker replacing docker on the horizon I don't see firecracker replacing v8 isolates for most edge function execution. Firstly, this article's scenario is a bit unusual in that they were using someone else's isolates - so adding on a few hops; secondly isolates running JS/TS can be statically analyzed quite well, and at scale looking historically for issues and exploits, in many edge compute scenarios this is quite desirable. MicroVMs can have an awful lot more flexibility so to get the same benefit you have to really lock down what is available - the trade-offs for mid-size companies seems to benefit isolates. Obviously netlify is more than big enough and relies heavily on this that it leans in their favour.

    1. dwroberts · · focus · HN ↗
      > I see firecracker replacing docker on the horizon

      I don’t think this is going to happen because they serve different purposes. Having to boot an entire OS inside a VM is a step backwards compared to containerisation. There are definitely use cases for isolating containers by running them inside a VM (see: Kata) but it generally ‘replacing’ docker, I don’t think that is on the horizon at all

      (Also: you need KVM available, you need a rootfs to boot which will be larger than a container, it has no built in support for mounts or really any kind of communication with the host unless you explicitly set up networking etc for it)

      1. jeroenhd · · focus · HN ↗
        > Having to boot an entire OS inside a VM

        The whole point of Firecracker over normal VM solutions is that "booting an OS" takes milliseconds.

        Still, I don't think Docker is at risk of being replaced just yet because of the resource management benefits you get from sharing a kernel.

        1. troupo · · focus · HN ↗
          > The whole point of Firecracker over normal VM solutions is that "booting an OS" takes milliseconds.

          Define "OS". A barebones OS will indeed start in microseconds. But then your app/service won't. Because it will likely need a gazillion things that a barebones OS doesn't provide. Suddenly the startup time isn't microseconds or even milliseconds.

          Sadly, we never got the promise of unikernels, and everything requires the full-blown OS to run anything

          1. pjmlp · · focus · HN ↗
            I would say that kind of got halfway there, when doing serverless.

            The gazillion things that the OS doesn't provide is taken care by language runtimes, which can perfectly run directly on top of type 1 hypervisors.

            In similar way how some of those languages have bare metal implementations for embedded development, where the runtime takes the OS role.

            Naturally on languages with thin runtimes and heavy reliance on POSIX like C and C++, this isn't as straightforward.

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.