Home Architecture Docs SDKs Get Started

Hardened at every layer

Hardware-level isolation, multi-node clustering, first-class SDKs, and built-in auth — everything you need to run untrusted code safely on your own infrastructure.

Firecracker MicroVMs

Each sandbox is a complete Linux virtual machine with its own kernel, root filesystem, and virtual network. Hardware-level isolation with sub-second boot times.

~250ms Cold Start

Firecracker boots a full Linux VM in under a quarter second from a cold start. Rootfs images are cached after first conversion. Snapshot warming pre-creates VM states for even faster restore.

Custom Kernels & Boot Args

Bring your own vmlinux kernel. Configurable boot arguments, NUMA node placement, I/O engine (Sync or Async io_uring), and shutdown timeouts per VM.

image-resolution.js
// Image resolution order — fastest to slowest
1. Committed image ID       // Instant
2. Committed image ref      // Instant (human-friendly tag)
3. Template name            // Cached ext4 snapshot
4. Imported tarball         // Local tar or ext4 files
5. Remote OCI image         // Pull + convert to ext4

Five-tier image resolution

Isolon resolves images through five tiers, from committed workspace snapshots (instant) to remote Docker Hub pulls (async conversion). Once converted, images are cached as ext4 rootfs files for sub-second subsequent boots.

OCI to ext4 conversion

Pulls Docker images from any registry and converts to bootable ext4 rootfs automatically.

Offline image imports

Import local tarballs or pre-converted ext4 images for air-gapped deployments.

In-VM builds

Build custom images from Dockerfiles inside a sandbox, no Docker daemon required on host.

Scale horizontally

Run one Commander and many Workers. Three scheduling strategies, automatic health checks, and circuit breakers for resilience.

Resource-Aware Scheduling

Default scheduler considers VM count, free memory, and CPU usage across all workers. Places workloads on the node with the most headroom, not just the fewest VMs.

Circuit Breakers

Per-worker circuit breakers trip after 3 consecutive failures, fast-failing requests for 15 seconds before a half-open retry. Prevents cascading timeouts.

Auto-Capacity Calculation

Workers calculate their own VM capacity from host CPU and memory if not explicitly configured. Reserves 2GB RAM for the host and applies 4x CPU overcommit.

Graceful Shutdown & Drain

Workers deregister on SIGTERM and stop accepting new workloads. Draining mode rejects new requests while existing VMs continue running.

cluster-config.json
{
  "mode": "commander",
  "cluster_token": "shared-secret",
  "cluster": {
    "scheduler": "resource-aware",
    "heartbeat_interval_seconds": 5,
    "worker_timeout_seconds": 30,
    "cb_failure_threshold": 3,
    "cb_reset_timeout_seconds": 15
  }
}

Hardened at every layer

Isolation is a stack, not a switch. From KVM hardware boundaries down to per-organization rate limits, every layer adds a new security boundary.

security-layers
Layer 1 Kernel — KVM hardware virtualization
vmexit, EPT, VT-x/AMD-V enforced boundaries
Layer 2 VMM — Firecracker MicroVM
Minimal attack surface, virtio devices only
Layer 3 Jailer — privilege drop + chroot
uid=<configured> gid=<configured>, empty chroot, no root
Layer 4 Seccomp — syscall whitelist
tightly restricted set, everything else blocked
Layer 5 Namespaces — PID, NET, IPC, MNT
Process isolation from host and other VMs
Layer 6 Cgroups — resource limits
CPU, memory, I/O quotas per VM
Layer 7 App — Auth, audit, rate limits
API keys, bcrypt, audit logs, token bucket

Hardened by Firecracker's Jailer

Before any VM boots, the VMM process is hardened by Firecracker's Jailer: privilege drop, chroot, seccomp-bpf, and namespace isolation. Four layers of defense before the first instruction executes.

Privilege drop + chroot

Jailer switches to a dedicated unprivileged user (configurable UID/GID) and locks the VMM into an empty chroot. The process never runs as root.

Seccomp-bpf whitelist

A tightly restricted set of syscalls is allowed. All others are blocked at the kernel level via seccomp-bpf. Exploiting the VMM surface is extremely difficult.

Namespaces + cgroups

PID, network, IPC, and mount namespaces isolate each VMM from the host and from other VMs. Resource limits via cgroups prevent noisy-neighbor attacks.

Minimal VMM attack surface

Firecracker is a purpose-built VMM with no PCI, no USB, no VGA — only virtio-block, virtio-net, and virtio-vsock. Less code means fewer bugs.

Scoped API Keys

Fine-grained permission scopes: workspaces:read/write/exec, files:read/write, images:read/write. Predefined roles for full_access, developer, read_only, and exec_only.

Audit Logging

Every workspace mutation is recorded: create, destroy, exec, file_write, set_internet, commit, pause, resume. Accessible via admin-only API endpoint.

Per-Org Rate Limiting

Token bucket rate limiting per organization. Configurable requests_per_second and burst size. Unauthenticated requests fallback to RemoteAddr as the bucket key.

Resource Quotas

Cap max workspaces per org, commits per workspace, total committed images globally, and auto-delete images older than N days.

SDKs, terminals, and real-time I/O

Three SDKs, a CLI, WebSocket terminals, and streaming APIs for every operation.

TypeScript SDK

Async/await API with typed errors, streaming exec output, file watchers, directory uploads/downloads, and REPL context sessions.

Python SDK

Blocking and async interfaces. Context managers, automatic sandbox cleanup, and bulk file transfers via tar archives.

Go SDK & CLI

Low-level client library for Go applications. Plus isolon-cli: create, exec, shell, snapshot, commit, and preview from the terminal.

WebSocket Terminals

Interactive PTY sessions via WebSocket. Resize, inject commands, and read output in real time from browser or SDK.

Streaming APIs

Stream exec output (HTTP chunked), file downloads, VM stats (Server-Sent Events), serial console logs, and background process output.

MCP Server

Native Model Context Protocol integration. AI agents create sandboxes, run commands, and read files via structured tool definitions.

Preview URLs

Generate short, shareable URLs for any port inside a sandbox. Reverse-proxy HTTP traffic through Isolon with automatic cleanup.

Git Operations

Clone, status, add, commit, push, pull, branch, and remote management — all inside the sandbox. Token-based authentication for private repos.

Metrics, webhooks, and logs

Built-in Prometheus metrics, HMAC-signed webhooks, and configurable file logging with rotation.

Prometheus Metrics

Counters and histograms for workspace creation, boot duration, exec latency, image cache hit rates, cluster worker health, and API request rates. Scraped from GET /metrics on every node.

Webhooks

HMAC-SHA256 signed HTTP callbacks for every lifecycle event. Multiple endpoints with per-endpoint event filtering. Exponential backoff retries with configurable timeout.

File Logging

Optional rotating file logs via lumberjack. Configurable max size, backup count, and gzip compression. Combined with HTTP request logging for full access trails.

VM Telemetry

Real-time CPU, memory, disk, and network stats per workspace. Available as single snapshots or Server-Sent Event streams for live dashboards.