microVM
The guest is assumed hostile.
A microVM does not save resources compared to a container: it boots its own kernel. The reason to use one is a different one.
An AI running open source tools is running code you cannot trust.
| Boundary | |
|---|---|
| Container | a namespace of a shared kernel |
| microVM | a hypervisor |
What is inside
Section titled “What is inside”- Firecracker on Linux (KVM). Virtualization.framework on macOS (
kling-vz). - A 6.1 kernel and a shared, read-only base image.
- A sparse overlay per machine: ~8 MB per running machine.
A cold boot is not enough
Section titled “A cold boot is not enough”Cold boot 2,643 msCreate the snapshot 305 msRestore from the snapshot ~30 msMeasured on Proxmox (i7-8700T), nested Firecracker. 2.6 s per request is useless. 30 ms is not. That is why everything rests on the golden template.