Skip to content

Shared folders

Your folder inside. No escaping it.

Terminal window
kling run -image toolchain -share ./repo:/work # copy: a read-only snapshot
kling -H ssh://lab run -share ./repo:/work # ... uploaded from your laptop
sudo kling config set daemon.share_roots /srv/code # on the daemon host, once
kling run -image toolchain -share /srv/code/app:/src:rw # live, read-write
mode what the guest sees host changes writes
copy a read-only ext4 copy no no
ro the live folder yes (≤ 1 s) no (EROFS)
rw the live folder yes (≤ 1 s) yes

Neither Firecracker nor the guest kernel has virtio-fs. NFS would expose a kernel server to hostile guests.

  • copy: the CLI packs a tar, the daemon validates every entry and builds an ext4.
  • ro / rw: the guest agent speaks FUSE itself and the daemon serves each operation with os.Root. Neither .. nor a symlink can leave the folder.

Live folders are only served under daemon.share_roots (empty by default). Live folders run at 16 MiB/s on Firecracker.