Run untrusted code from AI agents, CI pipelines, and multi-tenant users with hardware-level isolation. Each sandbox is a dedicated MicroVM with its own kernel, filesystem, and network — hardened before it even boots.
Containers share the host kernel. Isolon gives each workload its own kernel, filesystem, and network — hardware-level isolation on your own servers.
Create sandboxes via REST API, CLI, or SDKs. Isolon resolves the container image, converts it to a MicroVM rootfs, allocates a virtual network interface, and boots a Firecracker VM — all in under a quarter second.
Runs entirely on your Linux hosts with KVM. No third-party API keys or egress costs.
TypeScript, Python, and Go clients with typed errors, streaming I/O, and file transfer helpers.
Powerful CLI for terminal-centric workflows: create, exec, shell, snapshot, commit, and more.
Before any VM boots, Firecracker's Jailer hardens the VMM process with privilege drop, chroot, seccomp-bpf, and namespace isolation. Defense in depth, by design.
Jailer switches to a dedicated unprivileged user and locks itself into an empty chroot directory. The VMM never runs as root.
A tightly restricted whitelist of syscalls. Everything else is blocked at the kernel level. Exploiting the VMM surface is extremely difficult.
PID, network, IPC, and mount namespaces isolate each VMM. Resource limits via cgroups prevent noisy-neighbor attacks.
Each workload runs in its own MicroVM with a dedicated kernel and virtualized device model. Not containers — real VMs with hardware-enforced boundaries.
Each sandbox runs in its own MicroVM with a dedicated kernel, filesystem, and network stack. Hardware-enforced boundaries, not container namespaces.
Firecracker boots a full Linux VM in under a quarter second. No warm pools required — though snapshot warming is available.
Privilege drop, chroot, seccomp-bpf, and Linux namespaces. The VMM runs as an unprivileged user with a tightly restricted syscall whitelist.
Runs fully offline with pre-loaded images. Package the entire deployment — binaries, kernels, and rootfs — as a single tarball.
Commander/Worker architecture with three scheduling strategies. Circuit breakers, health checks, and auto-registration included.
Organizations, dashboard users, and scoped API keys with bcrypt hashing. No external identity provider required.
First-class SDKs with typed errors, streaming I/O, and file transfer. Plus a CLI for quick terminal workflows.
Native Model Context Protocol support. AI agents create sandboxes, execute commands, and read files via structured tools.
Interactive PTY sessions into running sandboxes. Resize, inject commands, and stream output in real time.
Built-in metrics for workspace counts, boot duration, exec latency, image cache rates, and cluster health. Ready for Grafana.
Run a single node for development, or scale out with a Commander/Worker cluster for production.
Everything in one process: API, VMs, dashboard, and SQLite database. Perfect for development and small deployments.
sudo ./isolon-server --mode standalone
Routes API requests to Workers with resource-aware scheduling. Lightweight — no VM infrastructure needed. Runs on macOS or Linux.
./isolon-server --mode commander
Runs VMs and reports to a Commander. Auto-calculates capacity from host CPU and memory. Supports graceful shutdown.
sudo ./isolon-server \
--mode worker \
--commander http://cmd:8080