Depending on what you are referring to exactly. I do not think that could be that much runtime performance difference between those, boot time is a different question.
I can't comment on performance, but on a different note it seems to be generally accepted that 'real' container boot time is slow - fly.io mention this too [0]. To add some numbers:
- 40ms for nsjail run an isolated command and exit [1]
- 150[2]-250ms to boot a firecracker microvm
- ~450ms for docker startup [3]
There are probably very good reasons for the difference (e.g. docker has layered filesystems to set up), but the default experience makes a difference.
We've related the timing we've seen on our platform, and the fact that Firecracker works surprisingly well with the performance envelope we need, but I wouldn't go so far as to say Fly has benchmarked Docker vs. Firecracker. We're just relating our experiences. Security isolation is dispositive for us; we'd be using Firecracker even if it slowed us down.
Generally speaking containers replicate networking && storage layers so are definitely much slower than a vm on public cloud, not to mention they generally live on vms.
However, in this context (being on a rpi) it probably wouldn't be the case.
Now, as for the firecracker discussion: Firecracker trades a faster boot time for a slower runtime as evidenced by this issue here:
Citation very needed, given that Firecracker is a VM and Docker runs binaries on bare metal. Maybe faster startup, but I'd want to see testing methods and data before I believe even that.