zlacker

[return to "Microsandbox: Virtual Machines that feel and perform like containers"]
1. jaunty+Ug[view] [source] 2025-05-30 15:13:26
>>makebo+(OP)
Why not some of the existing microvm efforts?

Cloud Hypervisor and Firecracker both have an excellent reputation for ultra lightweight VM's. Both are usable in the very popular Kata Containers project (as well as other upstart VM's Dragonball, & StratoVirt). In us by for example the CNCF Confidential Containers https://github.com/kata-containers/kata-containers/blob/main... https://confidentialcontainers.org/

There's also smaller efforts such as firecracker-containerd or Virtink, both which bring OCI powered microvms into a Docker like position (easy to slot into Kubernetes), via Firecracker and Cloud Hypervisor respectively. https://github.com/smartxworks/virtink https://github.com/firecracker-microvm/firecracker-container...

Poking around under the hood, microsandbox appears to use krun. There is krunvm for OCI support (includes MacOS/arm64 support!). https://github.com/containers/krunvm https://github.com/slp/krun

The orientation as a safe sandbox for AI / MCP tools is a very nicely packaged looking experience, and very well marketred. Congratulations! I'm still not sure why this warrants being it's own project.

◧◩
2. simonw+zh[view] [source] 2025-05-30 15:17:03
>>jaunty+Ug
If we get enough of these sandboxes, maybe we will finally get one that's easy for me to run on my own machines.
◧◩◪
3. mike_h+gi[view] [source] 2025-05-30 15:20:42
>>simonw+zh
Which platforms do you use?
◧◩◪◨
4. simonw+Qm[view] [source] 2025-05-30 15:46:43
>>mike_h+gi
macOS on my laptop, anything that runs in a container for when I deploy things.
◧◩◪◨⬒
5. tough+yq[view] [source] 2025-05-30 16:10:28
>>simonw+Qm
I had luck using ALVM which users Apple Hypervisor framework while exploring linux micro-vm's in macos fwiw https://github.com/mathetake/alvm
◧◩◪◨⬒⬓
6. simonw+sJ[view] [source] 2025-05-30 18:29:42
>>tough+yq
That looks really cool, but it's missing the one feature I want most from anything that runs a sandbox (or any security-related software): I need something which a billion dollar company with a professional security team is running in production on a daily basis.

So much of the solutions to this stuff I see come from a GitHub repo with a few dozen commits and often a README that says "do not rely on this software yet".

Definitely going to play with it a bit though, I love the idea of hooking into Apple's Hypervisor.framework (which absolutely fits my billion-dollar-company requirement.)

[go to top]