4 ms·
I'd like something like this but using firecracker VMs. Basically, a self hosted exe.dev. Anyone building or using a project like this?
by rsyring 4mo ago
I'd like something like this but using firecracker VMs. Basically, a self hosted exe.dev.
Anyone building or using a project like this?
- babhishek21 4mo agoAny particular reason why you want this with microVMs? Security (kernel separation) or snapshot support perhaps? A friend already made something similar for personal use, but using docker containers hardened with gVisor.
- Bnjoroge 4mo ago[flagged]
- sebmaynard 4mo agoAny suggestions?
- tastyeffectco 4mo agoThis project takes the Docker route instead of Firecracker — each container drops all capabilities, runs no-new-privileges, read-only rootfs, per-sandbox memory/PID limits, isolated networks. but! Not kernel-level separation like microVM. depending on use cases but its enough for most and way simpler to operate and maintain. If you need stronger isolation, the other replies in this thread mention (gVisor on k8s) Depends on your threat model and how much infra complexity you want to manage.
- dang 4mo agoCan you please not post AI-generated or AI-edited comments to HN? It's not allowed here - see https://news.ycombinator.com/newsguidelines.html#generated https://news.ycombinator.com/newsguidelines.html#generated and https://news.ycombinator.com/item?id=47340079 https://news.ycombinator.com/item?id=47340079. Of course, it's impossible to know for sure what was LLM processed or not, but some (not all!) of your posts are getting classified that way. You obviously have good points to make and are certainly welcome here! but if you'd please write text by hand which you plan to post to HN itself, we'd appreciate it. The community feels strongly about this right now.
- CGamesPlay 4mo agoI'm using https://coder.com https://coder.com for all my development containers. I've got mine hooked up to a k8s cluster, but anything that you can provision with Terraform can be used (e.g. docker containers).
- benldrmn 4mo agoI am working on https://github.com/isola-run/isola https://github.com/isola-run/isola which uses gVisor (not firecracker) on k8s (or something like kind, locally). Includes snapshotting, network controls and everything. Hope you could find this useful
- p2hari 4mo agoThis looks interesting. With auth and certs we might have something equivalent!
- umuttalha0 4mo ago[dead]
- cultofmetatron 4mo agofirecraker is optimized for lambda. ie: fire and forget. not so much live systems that maintain long running state. also, I dont' think you can run it on top of a hypervisor.
- p2hari 4mo ago+1 for this. Looking for something like exe.dev. self hosted . I tried using ionos cloud VPS , 4gig one could not handle even 3 basic web servers.
- bureado 4mo agohth: https://github.com/bureado/awesome-agent-runtime-security https://github.com/bureado/awesome-agent-runtime-security