12 comments

  • Normal_gaussian 7 hours ago
    I've been using SlicerVM extensively - which is Firecracker MicroVMs for the regular person (and for the irregular with their platform offering) - to run local 'edge' style workloads locally and securly. Agents, local dev CI, etc. It slotted in and replaced my proxmox vm orchestrator, and now I have secure and and fast vms on my laptop wherever I go. It also supports dockerfile style builds if you're wanting a security upgrade from containers (which, you should if you're using agents).

    Honestly, while I see firecracker replacing docker on the horizon I don't see firecracker replacing v8 isolates for most edge function execution. Firstly, this article's scenario is a bit unusual in that they were using someone else's isolates - so adding on a few hops; secondly isolates running JS/TS can be statically analyzed quite well, and at scale looking historically for issues and exploits, in many edge compute scenarios this is quite desirable. MicroVMs can have an awful lot more flexibility so to get the same benefit you have to really lock down what is available - the trade-offs for mid-size companies seems to benefit isolates. Obviously netlify is more than big enough and relies heavily on this that it leans in their favour.

  • nderjung 7 hours ago
    Alex from Unikraft here! Happy to answer any questions about the microVM part of the story from our side.

    We also did a couple of technical write ups if you're interested:

    - https://unikraft.com/blog/netlify-edge-functions

    - https://unikraft.com/customer-stories/edge-functions-netlify

  • yencabulator 5 hours ago
    > In the past, requests went out to a hosted execution service. Today, they run on MicroVMs inside our own edge network — roughly 5x faster at the median.

    So, the execution itself might now be slower as far as we know, they just eliminated some networking from the mix? Misleading.

  • nchmy 8 hours ago
    I'm having trouble understanding/believing this, given that Cloudflare Workers are also v8 isolates and run vastly faster than the 25-40ms that netlify says their isolates took...
    • phickey 8 hours ago
      from the article: "With our old infrastructure it went out over the internet, ran the edge function, and came back to us to pass on. With the new compute platform, the request is forwarded to a compute node within our network."

      As far as I know, Cloudflare Workers have always executed within Cloudflare's network, not gone out to the internet and executed elsewhere (which I read as being in a hyperscaler cloud).

    • irq-1 8 hours ago
      > In the past, requests went out to a hosted execution service. Today, they run on MicroVMs inside our own edge network

      The isolates were not being run at the edge.

      • bobfunk 7 hours ago
        They were running on the edge, and in the same datacenters but by another provider.
  • jedberg 7 hours ago
    The next time you want to curse AWS, remember they gave us Firecracker, one of the best microvm technologies out there, and the basis of at least a few non-AWS products out there (this one being the newest entry to the list).
    • Onavo 1 hour ago
      I don't think anybody hates AWS as a technology. It's mostly the rent-seeking (pricing almost-free bandwidth to an egregious level, nickel and diming users through fractional pricing calculations that are about as transparent as the US health insurance billing, predatory B2B vendor lock-in practices) that gets on people's nerves.

      When MBA (and YC startup) schools teach to build product with a "high switching cost", they do not have consumer's (in this case the developers) interests in mind.

      The other issue is that outside of the core offerings (S3, EC2/Lambdas, the logging and queuing services), everything else seems to be in a perpetual state of beta with products shipped by interns. The situation is not as bad as Cloudflare but the bar's on the ground. Pre-LLM, services like Cognito caused developers no end of pain and suffering. Poor documentation, buggy products opaque console UIs, there's no end to complaints when it comes to AWS. If their services were designed well, then companies like Vercel and Heroku shouldn't exist at all.

      And what's worse, with all of their efforts at squeezing customers, they still pay the worst of out of all of the big techs for non-senior leadership day to day engineering ICs. At least with Facebook there's commensurate pay. It's like Amazon took a look at Asian "996" culture and figured that if it works for their warehouse staff it should be good for the engineering folks too.

      • gottorf 15 minutes ago
        > companies like Vercel and Heroku shouldn't exist at all

        Crazy that Heroku with its head start has become abandonware. Goes to show that no incumbent is immune to change.

  • groundzeros2015 1 hour ago
    I don't think isolates are good idea. We need kernel level process isolation. Chrome itself doesn't trust isolates.
  • torginus 7 hours ago
    This is highly interesting considering AWS invented the MicroVMs for lambda, yet node on lambda is dog slow (both in latency and throughput). I can traumadump on request. I bet they could use some of this tech especially since their use cases are often not too dissimilar (auth validation, rule checking etc)
    • notatoad 3 hours ago
      seriously - if netlify can do 15ms warm start + 10ms cold start, wtf is lambda doing for the other 1500ms?
    • tomnipotent 6 hours ago
      > they could use some of this tech

      Firecracker is AWS tech, and was behind both Lambda & Fargate. I imagine it's all the enterprisey extras built on top that cause those issues.

      • nderjung 5 hours ago
        It is originally AWS, though we forked Firecracker ~4 years ago now and maintain an internal version with custom hypercalls (command-and-control from within the VM, POSIX-style fork, etc.) and a number of other features. We regularly pull patches and fixes from upstream Firecracker. You can read about the differences here:

        https://unikraft.com/blog/unikraft-vs-firecracker

        • tomnipotent 4 hours ago
          Weird time to advertise your product.
          • 0xCMP 2 hours ago
            ICYMI:

            > Over the past several months, our team has rebuilt the infrastructure behind Edge Functions, working closely with the team at Unikraft, who wrote about the experience from their side.

          • nderjung 2 hours ago
            Netlify use Unikraft for microVMs; just explaining the variant of Firecracker they are using.
          • fragmede 4 hours ago
            When would you prefer they advertise? Seems entirely relevant.
            • tomnipotent 3 hours ago
              When they're contributing to the conversation. It's not relevant.
              • fragmede 3 hours ago
                How is it not relevant? In what way doesn't it contribute?
                • tomnipotent 3 hours ago
                  It's on you to prove it does. In what ways does it contribute?
                  • fragmede 3 hours ago
                    We now know about their unikraft VM, whereas previous we did not.
                    • tomnipotent 3 hours ago
                      If only there was an HN guideline about not using the site primarily for promotion.
                      • fragmede 2 hours ago
                        You said they didn't contribute and weren't relevant. Whether their account primarily exists for promotion is a separate question.
      • zokier 5 hours ago
        fargate is not firecracker
        • binsquare 5 hours ago
          can confirm that this is true for the fargate product used by consumers.

          as someone who worked on it

        • tomnipotent 4 hours ago
          From the Firecracker README:

          https://github.com/firecracker-microvm/firecracker

          "Firecracker was developed at Amazon Web Services to accelerate the speed and efficiency of services like AWS Lambda and AWS Fargate."

  • CodesInChaos 6 hours ago
    > When the MicroVM boots up and the JavaScript server begins to listen on a port, we take a snapshot of the MicroVM. [...] we start a new MicroVM from that snapshot.

    That sounds scary, since forked RNG states can lead to catastrophic failures in UUID generators or cryptography.

  • aaronvg 8 hours ago
    Wish it explained where the v8 isolate latency is coming from compared to microvms
    • wmf 8 hours ago
      "In the past, requests went out to a hosted execution service."

      They were outsourcing to another company so there's plenty of room for overhead to creep in.

    • vmg12 8 hours ago
      v8 isolates aren't actually a great sandbox and I would not trust them implicitly in the AI era. This is probably why they wrap them in an additional sandbox.
      • torginus 7 hours ago
        But I guess they are good enough to isolate multiple instances of the same code, ran by the same customer in parallel.
        • Normal_gaussian 6 hours ago
          Without commenting on v8 isolates specifically, this doesn't necessarily hold in any isolation situation; many customers are running code on behalf of their customers, which are often submitting jobs on behalf of theirs, and so on. Isolation breaches within a platform customer can result in significant cross-user data breaches.
      • dummydummy1234 8 hours ago
        Why are v8 isolates bad, I see speculative execution hacks, but are there others?
        • phickey 8 hours ago
          Despite naming them isolates, the V8 team does not consider them to be a security boundary.
        • vmg12 7 hours ago
          The v8 JIT is very complex and can lead to sandbox escapes if there are type confusion bugs.
        • binsquare 8 hours ago
          v8 isolates are still shared kernel

          while microvm's are separate kernel + hardware virtualization through hypervisor guarantees

          I wouldn't call it bad either, just different tools for different things

          • londons_explore 7 hours ago
            Not only are they shared kernel... They're shared process, shared address space, shared memory pool and allocator... In fact, there is very little isolated about them at all.

            I bet there are a million ways to cause side channels allowing learning about other code or data on the same machine, and just one V8 bug (of which there have historically been thousands) let's you take over or modify code in another isolate.

  • ContinuityLab 3 hours ago
    [dead]
  • TaupeRanger 9 hours ago
    [flagged]
    • CharlesW 9 hours ago
      This is technical content, written for a technical audience, being shared on HN. In that context, it's not particularly esoteric. If "5x faster Edge Functions" means nothing to you, that's a good signal that you can just skip it without FOMO. If you're familiar with the concept but not Firecracker (a popular microVM) specifically, the expectation is that you'll use search engines and/or LLMs to get up to speed.
  • secondcoming 8 hours ago
    If you're counting milliseconds why use Javascript?
    • wmf 8 hours ago
      V8 is extremely optimized for script startup time.
    • nkmnz 7 hours ago
      V8 isn't written in JavaScript?