zlacker

[return to "Microsandbox: Virtual Machines that feel and perform like containers"]
1. jaunty+Ug[view] [source] 2025-05-30 15:13:26
>>makebo+(OP)
Why not some of the existing microvm efforts?

Cloud Hypervisor and Firecracker both have an excellent reputation for ultra lightweight VM's. Both are usable in the very popular Kata Containers project (as well as other upstart VM's Dragonball, & StratoVirt). In us by for example the CNCF Confidential Containers https://github.com/kata-containers/kata-containers/blob/main... https://confidentialcontainers.org/

There's also smaller efforts such as firecracker-containerd or Virtink, both which bring OCI powered microvms into a Docker like position (easy to slot into Kubernetes), via Firecracker and Cloud Hypervisor respectively. https://github.com/smartxworks/virtink https://github.com/firecracker-microvm/firecracker-container...

Poking around under the hood, microsandbox appears to use krun. There is krunvm for OCI support (includes MacOS/arm64 support!). https://github.com/containers/krunvm https://github.com/slp/krun

The orientation as a safe sandbox for AI / MCP tools is a very nicely packaged looking experience, and very well marketred. Congratulations! I'm still not sure why this warrants being it's own project.

◧◩
2. simonw+zh[view] [source] 2025-05-30 15:17:03
>>jaunty+Ug
If we get enough of these sandboxes, maybe we will finally get one that's easy for me to run on my own machines.
◧◩◪
3. tough+Ei[view] [source] 2025-05-30 15:23:01
>>simonw+zh
would you be OK with a -hardened- with default profiles docker containers one?
◧◩◪◨
4. appcyp+Zj[view] [source] 2025-05-30 15:32:08
>>tough+Ei
I don't understand what you mean? Can you clarify?
◧◩◪◨⬒
5. tough+Yq[view] [source] 2025-05-30 16:12:54
>>appcyp+Zj
sorry i meant to ask simon directly if they require a non-docker solution

im working on a wrapper that lets you swap runtimes and my first implementation is mostly a wrapper around docker containers

planning to add firecracker next

will explore adding microsandbox too cool stuff!

◧◩◪◨⬒⬓
6. simonw+9J[view] [source] 2025-05-30 18:27:56
>>tough+Yq
My ideal solution is non-Docker purely because I build software for other people to use. I don't want to have to tell my users "step 1: install Docker" if I can avoid it.
◧◩◪◨⬒⬓⬔
7. tough+jR[view] [source] 2025-05-30 19:34:58
>>simonw+9J
that does make sense, sadly firecracker seems to be mostly relegated to linux for now so there's no good multi-arch story i'm aware of
[go to top]