Features Architecture Docs SDKs Get Started
Self-hosted Firecracker MicroVMs

Secure, isolated sandboxes
on your infrastructure

Run untrusted code from AI agents, CI pipelines, and multi-tenant users with hardware-level isolation. Each sandbox is a dedicated MicroVM with its own kernel, filesystem, and network — hardened before it even boots.

~250ms Cold Start
Firecracker MicroVMs
3 SDKs + CLI
Jailer Privilege Drop
Air-Gap Ready

Isolation without the cloud

Containers share the host kernel. Isolon gives each workload its own kernel, filesystem, and network — hardware-level isolation on your own servers.

terminal
$./isolon-cli -url http://localhost:8080 create python:3.12-alpine
Created: ws-abc123-dead-beef
$./isolon-cli exec ws-abc123 "python --version"
Python 3.12.3
$./isolon-cli shell ws-abc123
root@ws-abc123:~#

Boot a VM in 250 milliseconds

Create sandboxes via REST API, CLI, or SDKs. Isolon resolves the container image, converts it to a MicroVM rootfs, allocates a virtual network interface, and boots a Firecracker VM — all in under a quarter second.

No cloud dependency

Runs entirely on your Linux hosts with KVM. No third-party API keys or egress costs.

First-class SDKs

TypeScript, Python, and Go clients with typed errors, streaming I/O, and file transfer helpers.

Command-line interface

Powerful CLI for terminal-centric workflows: create, exec, shell, snapshot, commit, and more.

isolon-server --mode standalone
[SECURITY] jailer uid=<configured> gid=<configured>
chroot: isolated filesystem jail
seccomp: restricted syscall whitelist
namespaces: PID, NET, IPC, MNT
cgroups: resource limits enforced
[SECURITY] workspace ws-abc123
KVM hardware isolation: active
virtio-blk: read-only rootfs
TAP network: 172.16.0.0/24 NAT

Hardened by Firecracker's Jailer

Before any VM boots, Firecracker's Jailer hardens the VMM process with privilege drop, chroot, seccomp-bpf, and namespace isolation. Defense in depth, by design.

Privilege drop + chroot

Jailer switches to a dedicated unprivileged user and locks itself into an empty chroot directory. The VMM never runs as root.

Seccomp-bpf sandbox

A tightly restricted whitelist of syscalls. Everything else is blocked at the kernel level. Exploiting the VMM surface is extremely difficult.

Namespaces + cgroups

PID, network, IPC, and mount namespaces isolate each VMM. Resource limits via cgroups prevent noisy-neighbor attacks.

KVM hardware isolation

Each workload runs in its own MicroVM with a dedicated kernel and virtualized device model. Not containers — real VMs with hardware-enforced boundaries.

Hardened execution, by design

~250ms Cold Start

Firecracker boots a full Linux VM in under a quarter second. No warm pools required — though snapshot warming is available.

Air-Gap Ready

Runs fully offline with pre-loaded images. Package the entire deployment — binaries, kernels, and rootfs — as a single tarball.

Built-In Authentication

Organizations, dashboard users, and scoped API keys with bcrypt hashing. No external identity provider required.

TypeScript, Python & Go

First-class SDKs with typed errors, streaming I/O, and file transfer. Plus a CLI for quick terminal workflows.

MCP Server

Native Model Context Protocol support. AI agents create sandboxes, execute commands, and read files via structured tools.

WebSocket Terminals

Interactive PTY sessions into running sandboxes. Resize, inject commands, and stream output in real time.

Prometheus Metrics

Built-in metrics for workspace counts, boot duration, exec latency, image cache rates, and cluster health. Ready for Grafana.

One binary, three modes

Run a single node for development, or scale out with a Commander/Worker cluster for production.

S

Standalone

Single node

Everything in one process: API, VMs, dashboard, and SQLite database. Perfect for development and small deployments.

sudo ./isolon-server --mode standalone
C

Commander

Cluster coordinator

Routes API requests to Workers with resource-aware scheduling. Lightweight — no VM infrastructure needed. Runs on macOS or Linux.

./isolon-server --mode commander
W

Worker

Compute node

Runs VMs and reports to a Commander. Auto-calculates capacity from host CPU and memory. Supports graceful shutdown.

sudo ./isolon-server \
  --mode worker \
  --commander http://cmd:8080

Ready to isolate your workloads?

Deploy in minutes on any Linux host with KVM. No cloud dependencies, no vendor lock-in.

Read the Docs