Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

25 USD/m to run a daemon on my own hardware. Yikes.
 help



That seems off to me as well.

Fwiw, you can run this instead free and open source: https://github.com/smol-machines/smolvm

Disclaimer: Am author.


Smolvm with it's libkrun vmm provides significantly worse security positioning than slicervms use of firecracker, which leads to slicervm for any dangerous or secure workload.

https://github.com/libkrun/libkrun


Libkrun and firecracker had similar foundations (Rust, KVM, rust-vmm).

Firecracker has a long track record but has a lot of knobs and tunings to get the security right.

smolvm's serve mode confines each VMM by default with a seccomp allowlist, Landlock, a per-VM uid and no_new_privs, much like Firecracker's jailer.

For dangerous workloads, people can do the same things such as skip host mounts and use virtio-net.

It's not a different security class just because it's libkrun vs firecracker


This looks amazing! The credential injection trick is particularly cool :)


you beat me to it (I'm singing the praises of smolmachines.com "smolvm" microvms all over the place)

Appreciate your support!

That is so effing cool — my only fear with it is whether you could turn it into a sustainable business, because I want that project to be around for a long time.

I'll keep it going just for you

amazing!

any point of comparison with microsandbox? [0]

[0] https://github.com/superradcompany/microsandbox


I focus on building the best VM tech.

Good sandboxing is a feature of a good VM.

Outside of that I support GPU and enables something called branchable computing.


Why is this better than just using Docker?

Kernel level isolation.

Functionality of criu built in so you can get rewind, pause, in an accessible manner.

Embeddable (you can write JavaScript to programmatically use an isolated environment)

Native performance on multiplatform + consistent experience across platforms.


This sounds great. By the way, does "kernel-level isolation" mean "you have to allocate a chunk of RAM to this"? Or is that CPU-level?

EDIT: Ah, looks like it means "runs its own kernel", not "isolates at the kernel" like Docker does.


yes, separate kernels + virtualized hardware via hypervisor.

containers are built on linux primitives & so shares the kernel.


Excellent, thank you. This is definitely useful to me.

I think Alex learned his lesson offering a free version running OpenFaaS.

The world: "build a secure, enterprise-ready microVM automation solution - work on it full time, and pay salaries for the staff that work on it"

Also: it has to be free.

So yes you're right, people confuse VC backed companies, and vibe-coded pet-projects for sustainable software.

SlicerVM was started in 2022 and internal only, plenty of YouTube videos and such about it - written completely manually from our Actuated work.

There's a free trial for anyone who wants to play about on their Mac or Linux computer, the comment here is from a real user (unprompted) that knew and used free alternatives previously.




Consider applying for YC's Winter 2027 batch! Applications are open till November 2.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: