| ▲ | Normal_gaussian 15 hours ago | |
Smolvm with it's libkrun vmm provides significantly worse security positioning than slicervms use of firecracker, which leads to slicervm for any dangerous or secure workload. | ||
| ▲ | binsquare 15 hours ago | parent [-] | |
Libkrun and firecracker had similar foundations (Rust, KVM, rust-vmm). Firecracker has a long track record but has a lot of knobs and tunings to get the security right. smolvm's serve mode confines each VMM by default with a seccomp allowlist, Landlock, a per-VM uid and no_new_privs, much like Firecracker's jailer. For dangerous workloads, people can do the same things such as skip host mounts and use virtio-net. It's not a different security class just because it's libkrun vs firecracker | ||