Honestly, while I see firecracker replacing docker on the horizon I don't see firecracker replacing v8 isolates for most edge function execution. Firstly, this article's scenario is a bit unusual in that they were using someone else's isolates - so adding on a few hops; secondly isolates running JS/TS can be statically analyzed quite well, and at scale looking historically for issues and exploits, in many edge compute scenarios this is quite desirable. MicroVMs can have an awful lot more flexibility so to get the same benefit you have to really lock down what is available - the trade-offs for mid-size companies seems to benefit isolates. Obviously netlify is more than big enough and relies heavily on this that it leans in their favour.
5x faster Edge Functions: V8 isolates to Firecracker MicroVMs (netlify.com)
Normal_gaussian 5 hours ago
jst1fthsdys 4 hours ago
binsquare 4 hours ago
Fwiw, you can run this instead free and open source: https://github.com/smol-machines/smolvm
Disclaimer: Am author.
QGQBGdeZREunxLe 3 hours ago
QGQBGdeZREunxLe 4 hours ago
innocent_name 4 hours ago
nderjung 6 hours ago
We also did a couple of technical write ups if you're interested:
- https://unikraft.com/blog/netlify-edge-functions
- https://unikraft.com/customer-stories/edge-functions-netlify
nchmy 6 hours ago
phickey 6 hours ago
As far as I know, Cloudflare Workers have always executed within Cloudflare's network, not gone out to the internet and executed elsewhere (which I read as being in a hyperscaler cloud).
irq-1 6 hours ago
The isolates were not being run at the edge.
bobfunk 5 hours ago
yencabulator 3 hours ago
So, the execution itself might now be slower as far as we know, they just eliminated some networking from the mix? Misleading.
jedberg 5 hours ago
CodesInChaos 4 hours ago
That sounds scary, since forked RNG states can lead to catastrophic failures in UUID generators or cryptography.
ameliaquining 4 hours ago
tybit 4 hours ago
torginus 5 hours ago
tomnipotent 4 hours ago
Firecracker is AWS tech, and was behind both Lambda & Fargate. I imagine it's all the enterprisey extras built on top that cause those issues.
nderjung 4 hours ago
tomnipotent 2 hours ago
fragmede 2 hours ago
tomnipotent an hour ago
fragmede an hour ago
tomnipotent 40 minutes ago
fragmede 38 minutes ago
tomnipotent 37 minutes ago
fragmede 21 minutes ago
nderjung 17 minutes ago
zokier 3 hours ago
binsquare 3 hours ago
as someone who worked on it
tomnipotent 2 hours ago
https://github.com/firecracker-microvm/firecracker
"Firecracker was developed at Amazon Web Services to accelerate the speed and efficiency of services like AWS Lambda and AWS Fargate."
notatoad an hour ago
aaronvg 6 hours ago
vmg12 6 hours ago
dummydummy1234 6 hours ago
binsquare 6 hours ago
while microvm's are separate kernel + hardware virtualization through hypervisor guarantees
I wouldn't call it bad either, just different tools for different things
londons_explore 5 hours ago
I bet there are a million ways to cause side channels allowing learning about other code or data on the same machine, and just one V8 bug (of which there have historically been thousands) let's you take over or modify code in another isolate.
phickey 6 hours ago
vmg12 5 hours ago
torginus 5 hours ago
Normal_gaussian 5 hours ago
wmf 6 hours ago
They were outsourcing to another company so there's plenty of room for overhead to creep in.
secondcoming 6 hours ago
wmf 6 hours ago
nkmnz 5 hours ago