Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
benswerd
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
6 ms
·
61.
▲
by
benswerd
6mo ago
It is impossible. Our tech is not decades old so there is a chance we've missed something but our layer management is atomic so I'd be shocked if you'd be able to corrupt state across forks/snapshots.
62.
▲
by
benswerd
6mo ago
Generally kernel level attacks and neighbor performance impacts on the security side. On the functional side without a kernel per guest you can't allow kernel access for stuff like eBPF, networking, nested virtualization and lots of im
63.
▲
by
benswerd
6mo ago
So forking across multiple nodes in that speed is not possible — we run extremely beefy nodes in order to avoid moving VMs across nodes as much as possible. We are researching systems of hot moving VMs across VMs but it would have very diff
64.
▲
by
benswerd
6mo ago
So thats what we did. We've made forking a whole gas town performant in 100s of milliseconds. Try it — you can definitely see it working on free tier. In respect to large and powerful RAM + Size is important but I was more-so referring
65.
▲
by
benswerd
6mo ago
Great for simple things, but git worktrees don't work when you have to fork processes like postgres/complex apps.
66.
▲
by
benswerd
6mo ago
Proxmox forking in a few seconds is a miracle! These are likely only a better value for you at large scale/if you start wanting to run hundreds.
67.
▲
by
benswerd
6mo ago
Generally compared to those two more powerful. Freestyle VMs are full Debian machines, with support for sysd, docker in docker, multiple users, hardware virtualization etc. Daytona and E2B are both great "sandbox" providers but do
68.
▲
by
benswerd
6mo ago
Ah we cannot do this without a restart. Hot pluggable ram is something I'm interested in but is currently a backburner feature.
69.
▲
by
benswerd
6mo ago
50 is not heavy, what is heavy is 1000 VMs that can be paused/brought back 50 in 1 second. Though generally ya, handrolling this stuff can work at the scale of 50 VMs, it becomes a lot harder once you hit hundreds/thousands.
70.
▲
by
benswerd
6mo ago
So fork time is actually O(1) with VM size, its 500ms even for 64gb + disk. We're using some pretty weird COW techniques to pull it off.
71.
▲
by
benswerd
6mo ago
Yes! You can def run something like K3s in these VMs.
72.
▲
by
benswerd
6mo ago
Never tried them, I think the weird thing about VM providers is the difference really all is in the execution. These guys seem great in concept but I don’t know enough about how they properly work.
73.
▲
by
benswerd
6mo ago
Our users are platforms, and many of the best already build on us. Self hosting is a valuable feature but our technology is unfriendly to small nodes — it will not work on consumer hardware. Many of the optimizations we spend our time on on
74.
▲
by
benswerd
6mo ago
Tx it took a lot of work lol
75.
▲
by
benswerd
6mo ago
That’s what I’m hoping for!
76.
▲
by
benswerd
6mo ago
So the snapshotting tech is actually 100% independent of Git. Git is useful for branching vs forking (IE you can't merge two VM forks back together), but all the tech I showed in the Loom exists independently from Git. The hard part of
77.
▲
by
benswerd
6mo ago
So we have there are 3 solutions to this, Freestyle supports 2 of them: 1. Freestyle supports multiple linux users. All linux users on the VM are locked down, so its safe to have a part of the vm that has your secret keys/code that the
78.
▲
by
benswerd
6mo ago
If you put your gmail credentials into a VM that an AI Agent dealing with untrusted prompts has access to they should be treated as leaked and be disabled immediately. However, if you don't put your administrative credentials inside of
79.
▲
by
benswerd
6mo ago
yep you can choose ram + disk + cpu size
80.
▲
by
benswerd
6mo ago
This will just work on us. We do auto suspend depending on your configured timeout. We'll pause your VM and when you come back the processes will be in the exact same state as when you left.
81.
▲
by
benswerd
6mo ago
Kind of. The chat logs of the agent are trustworthly, as should any telemetry you have on it or coming out of the VM. Its behavior should be treated as probabilistic and therefore untrustworthly.
82.
▲
by
benswerd
6mo ago
Deterministic testing of edge cases. It can be really hard to recreate weird edge cases of running services, but if you can create them we can snapshot them exactly as they are.
83.
▲
by
benswerd
6mo ago
no, but the goal of these is if you are faced with prompt injection the worst case scenario is the AI uses that computer badly.
84.
▲
by
benswerd
6mo ago
I used to believe this, but I think the next generation of agents is much more autonomous and just needs a computer. The work of a developer is open ended, so we use a computer for it. We don't try to box developers into small granular
85.
▲
by
benswerd
6mo ago
Exe.dev is a individual developer oriented service. Freestyle is more oriented at platforms building the next exe.dev. Thats why our pricing is usage based and we have a much larger API surface.
86.
▲
by
benswerd
6mo ago
I recommend running the agent harness outside of the computer. The mental model I like to use is the computer is a tool the agent is using, and anything in the computer is untrusted.
87.
▲
by
benswerd
6mo ago
So we recommend branch per fork, merge what you like. You have to change the branch on each fork individually currently and thats unlikely to change in the short term due to the complexity of git internals, but its not that hard to do yours
88.
▲
by
benswerd
6mo ago
500ms. Less than 1 second. We're aiming to get that down to 200ms in the next 3 months.
89.
▲
by
benswerd
6mo ago
So first MicroVM != Container, and container is not a secure isolation system. I would not run untrusted containers on your nodes without extra hardening. The memory forking was originally invented because for AI App Builders and first resp
90.
▲
by
benswerd
6mo ago
So isolation is correct. Forking a sandbox gives you multiple exact duplicates of isolated environments. When your coding agent has 10 ideas for what to do, to evaluate them correctly it needs to be able to evaluate them in isolation. If yo
More ›