Hardware-level isolation, multi-node clustering, first-class SDKs, and built-in auth — everything you need to run untrusted code safely on your own infrastructure.
Each sandbox is a complete Linux virtual machine with its own kernel, root filesystem, and virtual network. Hardware-level isolation with sub-second boot times.
Each sandbox runs in its own MicroVM with a dedicated kernel (vmlinux), root filesystem (ext4), and virtual network interface (TAP). Memory and CPU are fully isolated from the host and other VMs. No shared kernel like containers.
Firecracker boots a full Linux VM in under a quarter second from a cold start. Rootfs images are cached after first conversion. Snapshot warming pre-creates VM states for even faster restore.
Bring your own vmlinux kernel. Configurable boot arguments, NUMA node placement, I/O engine (Sync or Async io_uring), and shutdown timeouts per VM.
// Image resolution order — fastest to slowest
1. Committed image ID // Instant
2. Committed image ref // Instant (human-friendly tag)
3. Template name // Cached ext4 snapshot
4. Imported tarball // Local tar or ext4 files
5. Remote OCI image // Pull + convert to ext4
Isolon resolves images through five tiers, from committed workspace snapshots (instant) to remote Docker Hub pulls (async conversion). Once converted, images are cached as ext4 rootfs files for sub-second subsequent boots.
Pulls Docker images from any registry and converts to bootable ext4 rootfs automatically.
Import local tarballs or pre-converted ext4 images for air-gapped deployments.
Build custom images from Dockerfiles inside a sandbox, no Docker daemon required on host.
Run one Commander and many Workers. Three scheduling strategies, automatic health checks, and circuit breakers for resilience.
Default scheduler considers VM count, free memory, and CPU usage across all workers. Places workloads on the node with the most headroom, not just the fewest VMs.
Per-worker circuit breakers trip after 3 consecutive failures, fast-failing requests for 15 seconds before a half-open retry. Prevents cascading timeouts.
Workers calculate their own VM capacity from host CPU and memory if not explicitly configured. Reserves 2GB RAM for the host and applies 4x CPU overcommit.
Workers deregister on SIGTERM and stop accepting new workloads. Draining mode rejects new requests while existing VMs continue running.
{
"mode": "commander",
"cluster_token": "shared-secret",
"cluster": {
"scheduler": "resource-aware",
"heartbeat_interval_seconds": 5,
"worker_timeout_seconds": 30,
"cb_failure_threshold": 3,
"cb_reset_timeout_seconds": 15
}
}
Isolation is a stack, not a switch. From KVM hardware boundaries down to per-organization rate limits, every layer adds a new security boundary.
Before any VM boots, the VMM process is hardened by Firecracker's Jailer: privilege drop, chroot, seccomp-bpf, and namespace isolation. Four layers of defense before the first instruction executes.
Jailer switches to a dedicated unprivileged user (configurable UID/GID) and locks the VMM into an empty chroot. The process never runs as root.
A tightly restricted set of syscalls is allowed. All others are blocked at the kernel level via seccomp-bpf. Exploiting the VMM surface is extremely difficult.
PID, network, IPC, and mount namespaces isolate each VMM from the host and from other VMs. Resource limits via cgroups prevent noisy-neighbor attacks.
Firecracker is a purpose-built VMM with no PCI, no USB, no VGA — only virtio-block, virtio-net, and virtio-vsock. Less code means fewer bugs.
Organizations, dashboard users, and scoped API keys. Supports session cookies for the React dashboard and Bearer tokens for SDK access. All credentials stored with bcrypt hashing in SQLite.
Fine-grained permission scopes: workspaces:read/write/exec, files:read/write, images:read/write. Predefined roles for full_access, developer, read_only, and exec_only.
Every workspace mutation is recorded: create, destroy, exec, file_write, set_internet, commit, pause, resume. Accessible via admin-only API endpoint.
Token bucket rate limiting per organization. Configurable requests_per_second and burst size. Unauthenticated requests fallback to RemoteAddr as the bucket key.
Cap max workspaces per org, commits per workspace, total committed images globally, and auto-delete images older than N days.
Three SDKs, a CLI, WebSocket terminals, and streaming APIs for every operation.
Async/await API with typed errors, streaming exec output, file watchers, directory uploads/downloads, and REPL context sessions.
Blocking and async interfaces. Context managers, automatic sandbox cleanup, and bulk file transfers via tar archives.
Low-level client library for Go applications. Plus isolon-cli: create, exec, shell, snapshot, commit, and preview from the terminal.
Interactive PTY sessions via WebSocket. Resize, inject commands, and read output in real time from browser or SDK.
Stream exec output (HTTP chunked), file downloads, VM stats (Server-Sent Events), serial console logs, and background process output.
Native Model Context Protocol integration. AI agents create sandboxes, run commands, and read files via structured tool definitions.
Generate short, shareable URLs for any port inside a sandbox. Reverse-proxy HTTP traffic through Isolon with automatic cleanup.
Clone, status, add, commit, push, pull, branch, and remote management — all inside the sandbox. Token-based authentication for private repos.
Built-in Prometheus metrics, HMAC-signed webhooks, and configurable file logging with rotation.
Counters and histograms for workspace creation, boot duration, exec latency, image cache hit rates, cluster worker health, and API request rates. Scraped from GET /metrics on every node.
HMAC-SHA256 signed HTTP callbacks for every lifecycle event. Multiple endpoints with per-endpoint event filtering. Exponential backoff retries with configurable timeout.
Optional rotating file logs via lumberjack. Configurable max size, backup count, and gzip compression. Combined with HTTP request logging for full access trails.
Real-time CPU, memory, disk, and network stats per workspace. Available as single snapshots or Server-Sent Event streams for live dashboards.