Remix.run Logo
▲ binsquare a day ago

That seems off to me as well.

Fwiw, you can run this instead free and open source: https://github.com/smol-machines/smolvm

Disclaimer: Am author.

▲Normal_gaussian 14 hours ago | parent | next [-]

Smolvm with it's libkrun vmm provides significantly worse security positioning than slicervms use of firecracker, which leads to slicervm for any dangerous or secure workload.

https://github.com/libkrun/libkrun

▲binsquare 14 hours ago | parent [-]

Libkrun and firecracker had similar foundations (Rust, KVM, rust-vmm).

Firecracker has a long track record but has a lot of knobs and tunings to get the security right.

smolvm's serve mode confines each VMM by default with a seccomp allowlist, Landlock, a per-VM uid and no_new_privs, much like Firecracker's jailer.

For dangerous workloads, people can do the same things such as skip host mounts and use virtio-net.

It's not a different security class just because it's libkrun vs firecracker

▲Cyph0n a day ago | parent | prev | next [-]

This looks amazing! The credential injection trick is particularly cool :)

▲chrisweekly 19 hours ago | parent | prev | next [-]

you beat me to it (I'm singing the praises of smolmachines.com "smolvm" microvms all over the place)

▲binsquare 19 hours ago | parent [-]

Appreciate your support!

▲QGQBGdeZREunxLe a day ago | parent | prev | next [-]

Brew tap: https://github.com/smol-machines/homebrew-tap

▲zmmmmm 16 hours ago | parent | prev | next [-]

amazing!

any point of comparison with microsandbox? [0]

[0] https://github.com/superradcompany/microsandbox

▲binsquare 15 hours ago | parent [-]

I focus on building the best VM tech.

Good sandboxing is a feature of a good VM.

Outside of that I support GPU and enables something called branchable computing.

▲tomjen3 5 hours ago | parent | prev | next [-]

That is so effing cool — my only fear with it is whether you could turn it into a sustainable business, because I want that project to be around for a long time.

▲binsquare 2 hours ago | parent [-]

I'll keep it going just for you

▲dprkh 18 hours ago | parent | prev [-]

Why is this better than just using Docker?

▲binsquare 17 hours ago | parent [-]

Kernel level isolation.

Functionality of criu built in so you can get rewind, pause, in an accessible manner.

Embeddable (you can write JavaScript to programmatically use an isolated environment)

Native performance on multiplatform + consistent experience across platforms.

▲stavros 16 hours ago | parent [-]

This sounds great. By the way, does "kernel-level isolation" mean "you have to allocate a chunk of RAM to this"? Or is that CPU-level?

EDIT: Ah, looks like it means "runs its own kernel", not "isolates at the kernel" like Docker does.

▲binsquare 15 hours ago | parent [-]

yes, separate kernels + virtualized hardware via hypervisor.

containers are built on linux primitives & so shares the kernel.

▲stavros 14 hours ago | parent [-]

Excellent, thank you. This is definitely useful to me.