Remix.run Logo
▲ chubot 4 hours ago

As far as I know, Firecracker, gVisor, and Kata Containers are the solution here. They use VM primitives (x64_64 and ARM64 extensions) and have lighter codebases

https://firecracker-microvm.github.io/

https://gvisor.dev/

https://katacontainers.io/

But I don't have any direct experience with any of them. I'd be curious what people who have built on top of them think

edit: OK it looks like Kata can use Firecracker, so as far as isolation, it's either Firecracker or gVisor. And Firecracker is the VMM I mentioned, but gVisor is quite different -- it's more like a user space kernel that emulates syscalls.

▲binsquare 4 hours ago | parent | next [-]

I'm going to toss in smolvm as well because firecracker needs some expertise to make the box usable and secure.

https://github.com/smol-machines/smolvm

▲johnsmith1840 2 hours ago | parent | prev | next [-]

I've deploy gvisor, done basic test of firecracker and an honest attempt at production kata.

Firecracker and gvisor are nice systems not horrible to use, gvisor isn't quite the same security level though.

Kata is HARD to make. The technical know how to make that in production is awe inspiring. I wanted to use it but it was so complicated to integrate into a cluster I literally just gave up and mirrored raw VMs into the cluster which was alot easier actually.

Kata also breaks any potential of confidential VM unless you're a virtualization wizard.

You should go check out redhat's confidential container method for a production design overview. Their ARO self hosted system.

▲laurencerowe 4 hours ago | parent | prev [-]

As I understand it Kata supports multiple VMM backends, Firecracker, QEmu, Cloud Hypervisor, and their own Dragonball. Except QEmu, I believe those are all built on crates in the rust-vmm ecosystem, each making slightly different tradeoffs.