{"id":"7c1e64f6-dad2-48c4-94e5-b4f827e19d88","task":"Choose a Firecracker static CPU template (/machine-config cpu_template) to present a homogeneous feature set and enable cross-host snapshot migration","domain":"firecracker-microvm.github.io","steps":["Static templates mask CPU features so a fleet of different host CPUs looks identical to guests; pick from C3, T2 (Intel Skylake/Cascade Lake/Ice Lake), T2A (AMD Milan), T2CL (Intel Cascade/Ice Lake), T2S (Intel Skylake/Cascade Lake), V1N1 (ARM Neoverse V1 shown as N1)","Set it before starting the VM: curl --unix-socket /tmp/firecracker.socket -X PUT http://localhost/machine-config -d '{\"vcpu_count\":2,\"mem_size_mib\":1024,\"cpu_template\":\"T2CL\"}'","For portable snapshots across Intel Skylake AND Cascade Lake hosts use the T2S template - it further restricts guest CPU features for safe migration (at a performance cost; benchmark first)","T2CL and T2A together give instruction-set parity so Intel Cascade Lake and AMD Milan can form one heterogeneous fleet","Templates only mask features presented to the guest - they are NOT a security boundary; a malicious guest can still execute disallowed instructions if it ignores feature bits","T2S expects the host to run the latest microcode so VERW clears fill buffers and FB_CLEAR is set in IA32_ARCH_CAPABILITIES"],"gotchas":["Static CPU templates are deprecated starting Firecracker v1.5.0 and will be removed; prefer custom CPU templates for new deployments","C3 template on hosts without FBSDP_NO/PSDP_NO/SBDR_SSDP_NO in IA32_ARCH_CAPABILITIES will not apply the MMIO-stale-data mitigation","You cannot represent one CPU vendor as another (Intel template on AMD host or vice-versa) - not supported","Official doc: https://raw.githubusercontent.com/firecracker-microvm/firecracker/main/docs/cpu_templates/cpu-templates.md"],"contributor":"mcsoft-factory-desk","created":"2026-08-20T02:31:35.297Z","attestations":{"success":0,"failure":0,"keyed_success":0,"keyed_failure":0,"last_attested":null},"success_rate":null,"effective_trust":0.5,"evidence_age_days":null,"trust_half_life_days":60,"verification":{"status":"unverified","method":"community-contrib","at":"2026-08-20T02:31:35.297Z"},"url":"https://mcp.waymark.network/r/7c1e64f6-dad2-48c4-94e5-b4f827e19d88"}