4 ms·
Show HN: We Put Chromium on a Unikernel (OSS Apache 2.0)
We’ve been building infrastructure to spin up browsers for AI agents. Originally, we built[0] it as a pool of warm Docker containers running Chromium, exposing:
- Chrome DevTools Protocol (for Playwright/Puppeteer)
- noVNC (for live view)
We’ve been following the unikernel space for a while, so we decided to see if we could get our image on one. We went with Unikraft Cloud[1]. Here’s how it did:
- Boot-up time: 10–20ms (vs. ~5s for Docker containers)
- Near 0 CPU/memory consumption when idle
- Still ~8GB RAM when active (headful Chromium)
Potential use cases:
- Standby mode during long-running jobs: unikernels can sleep after X sec of inactivity, reducing clock time costs
- Session reuse: auth/session cookies persist for hours/days. Basically as long as the cookies are valid
- Cold start speed: good for low-latency, event-based handling
We open sourced it with Apache 2.0! Feel free to fork or submit an issue / PR. Open to feedback or suggestions. www.github.com/onkernel/kernel-images
==
[0] https://github.com/onkernel/kernel-images https://github.com/onkernel/kernel-images
[1] https://unikraft.cloud/ https://unikraft.cloud/
[2] Thanks to the Unikraft Cloud team @fhuici @nderjung @razvandeax for helping us figure this out (we're not affiliated)
[3] (OPs) @rgarcia @juecd
- juecd 1y ago(OP) Happy to answer any questions! Some things we're still exploring: - Mounting persistent storage for file i/o - Replacing noVNC with a faster alternative Would love feedback, especially if you’ve worked on fast-cold-start systems or unikernel-based infra.
- kjok 1y agoHow does fast-cold-start help here? What use cases did it enable that were previously not possible with a warm pool of Docker containers?
- juecd 1y agoThe big motivation we had for trying to do this on a unikernel is actually the session pause/resume. The fast cold restart is a nice addition (or put the other way, a super slow restart would prohibit session pause/resume from being useful)
- jay-barronville 1y agoImpressive work, @juecd!
- shaqbert 1y ago5s for Docker containers vs 20ms now ... holy moly, this is fast
- juecd 1y agoFrom what we've seen, micro VMs could probably do something very fast too (150ms?) but we thought 20ms was pretty crazy.
- rollcat 1y agoInteresting work. It immediately brought boot2gecko to my mind. If I understand unikernels correctly - do you think it would be viable to run this on real HW?
- shykes 1y agoThis looks excellent, and very fun to play with! I used this one-liner to run an instance directly from remote source: dagger -c 'git https://github.com/onkernel/kernel-images | head | tree | docker-build --dockerfile containers/docker/Dockerfile | up --ports 8501:8501,8080:8080,6080:6080,9222:9222' Be aware that the initial docker build is quite long... But caching kicks in for subsequent runs. I look forward to playing with this!
- chatmasta 1y agoI just wanna say the Dagger shell syntax is incredibly cool and I look forward to playing with it. I would not complain if you posted such self-promotional comments on any thread where it’s relevant because it goes to show the flexibility of the thing. I saw your announcement post / many contentious HN comments, but wanted to chime in here with a supportive take, because I think time will reveal this design to be very compelling.
- shykes 1y agoThank you, I appreciate that! I actually agonized over whether to include this particular one-liner, because of the risk of perceived self-promotion. In the end I decided to include it, because I actually used it, and I found it actually useful for anyone who wants to try Kernel with a one-liner. I made sure to not include a link to my project, to keep my karma in balance :) I've been a fan of unikernels for a long time (we acquired the original Unikernel company at Docker), and I have to say applying it to browsers is genius. Now I'm surprised the unikernel community hasn't focused on this application sooner.
- tyre 1y agoThis is super cool. We’ve been looking into infra for AI agents. As others have noted, the difference in speed alone between docker and this is a huge win. Having our clients wait around for five seconds really adds up. Awesome tech, excited to dig deeper for healthcare
- juecd 1y agoThank you!
- capiki 1y agoCool (and congrats on the demo)! Sounds like a promising approach. I work on browser use agents and one of the most difficult problems now is bot detection. Curious if you know how this impacts bot detection/fingerprinting?
- juecd 1y agoThank you! Yeah, the current implementation basically performs the same as a Docker container (i.e. not much). The interface is the same, so you can use BU/Playwright/Puppeteer's header configs to change as needed. We did notice the unikernel cloud instances don't run into bot detection as often as our hosted docker instances, but I think that's mostly because Cloudflare haven't flagged Unikraft Cloud's IPs yet, hah.
- ATechGuy 1y agoWhy detect "bots" when you can block them using captchas/proof-of-work solutions. Curious to know your use case for detecting bots.
- tecleandor 1y agoI feel like their use case it's the other way around: avoid being detected as a bot.
- juecd 1y agoYes
- HyprMusic 1y agoI'm assuming the low latency cold starts are from a paused state, considering chrome itself takes a few seconds to boot? Or have you found some clever way to snapshot a running chrome and fork that? Either way thanks for sharing.
- rgarcia 1y agoIt snapshots / pauses the entire unikernel instance after launching chromium, and then resumes the instance in <20ms with exactly the same state.
- yjftsjthsd-h 1y agoIs that safe? I was under the impression that snapshot/resume of ex. anything running crypto libraries was a minefield of duplicate keys and reused nonces.
- crowcroft 1y agoThis is probably a dumb question from someone who knows almost nothing about system engineering. How hard would it be to boot a computer to this as an OS?
- csdvrx 1y agoYou would have to add support for the peripherals in the kernel, and have some kind of init system. You would also need a filesystem supported to boot the computer. I was doing something similar for the entire OS a few years ago: cosmopolinux, a distribution of cosmopolitan binaries: https://github.com/csdvrx/cosmopolinux https://github.com/csdvrx/cosmopolinux My idea was to replace the WSL binaries to have a Linux distribution living on C:\, but that could also be booted baremetal if you didn't want to use Windows I had to put together a multi stage init system for that: if you get the ISO, you can put in on a thumbdrive and boot it: https://gitlab.com/csdvrx/cosmopolinux https://gitlab.com/csdvrx/cosmopolinux The only difference between them is the kernel and the filesystem: the github NTFS has a firecracker linux kernel, the gitlab ISO has a regular kernel with many modules. I wanted to do a full NTFS solution but I couldn't find a bootloader I liked that would support booting from a NTFS partition. Booting from an ISO was simpler and faster.
- yjftsjthsd-h 1y ago> I wanted to do a full NTFS solution but I couldn't find a bootloader I liked that would support booting from a NTFS partition. Could you stick the Linux kernel and initramfs on the EFI boot partition as a UKI, and then just tell it about its rootfs being on the NTFS C drive? You don't really need any bootloader except the firmware's UEFI implementation on most modern PCs, and Linux supports NTFS.
- csdvrx 1y ago> Could you stick the Linux kernel and initramfs on the EFI boot partition as a UKI I considered that, even if it would go against the idea of having everything inside the Windows partition. I'd rather have had a shim in the EFI, with the UKI in C:\ The difficulty was bitlocker: my approach was a UKI with a small kernel and a few binaries to open the bitlocker volume and kexec the bigger kernel. I was also exploring how to mark part of the NTFS volume as unusable to stick a different payload there. The "ISO on a thumbdrive" was done to get baremetal boot working and out of the way, to see if I needed deeper changes to what had started as a 2 stages boot process, or if it was good enough as-as. > Linux supports NTFS. The kernel module is great! I wish there was a linux distribution that could be run from either WSL or baremetal, to get more people familiar with baremetal linux.
- daniel_levine 1y agoThis is awesome stuff. I think the biggest thing holding back a bunch agentic use cases is great infra and this is a a great step in the right direction. Love how fast it boots!
- LoganDark 1y ago> This unikernel implementation can only be run on Unikraft Cloud Looking forward to one that'll run on my local machine, if I read this correctly?
- juecd 1y agoYeah, there are some nuances to Unikraft Cloud that their team did to get it running. I'll see if they can chime in and shed some light!
- eyberg 1y agoMaybe you can clarify but this isn't actually using unikraft the kernel is it? Maybe you can clarify that this is actually running a stripped down linux as unikraft does not have the support to run chrome itself.
- moltar 1y agoWhat’s the size of the image? Can this run inside a Lambda?
- juecd 1y agoHaven't tried on a Lambda. Would be curious to know the results if you do! It took us 8gb to get it up - maybe could be slimmed down if you took out the Anthropic Computer Use components, but browsers generally are pretty heavy.
- dbmikus 1y agoWhen should I use this versus Browserbase or Browserless or Hyperbrowser? Obviously since this is open source, then I can self host it. What other reasons? Just curious!
- juecd 1y agoYeah, this is mostly just an OSS implementation for self-hosting! I'm not entirely sure what any of those companies use under the hood, in theory they could use this implementation if they wanted to gain the fast boot times, session reuse etc.
- gregpr07 1y agoWooow man this is crazy!! I wanna chat