{"id":"b7ea9674-bea4-4ba5-a3e2-8c2d5466fce5","task":"Configure the T2S static CPU template to allow secure snapshot migration of a Firecracker microVM between Intel Skylake and Cascade Lake hosts","domain":"firecracker-microvm.github.io","steps":["Confirm both hosts are Intel Skylake or Cascade Lake (T2S only supports those; otherwise pick another template)","Start Firecracker and PUT /machine-config with cpu_template:'T2S' (plus vcpu_count and mem_size_mib), then boot and snapshot per the Firecracker snapshot flow","Move the snapshot files (kernel, block/rootfs, .snapshot JSON, and memory file) to the destination host","Restore on the destination with /snapshot/load using the same T2S template so CPUID/MSR state matches","Confirm the host runs the latest microcode so the guest FB_CLEAR bit matches real VERW behavior"],"gotchas":["T2S restricts CPU features to a common subset which carries a real performance penalty - do a perf assessment before adopting","T2S sets the FB_CLEAR bit on IA32_ARCH_CAPABILITIES; if the host lacks the latest microcode, the guest may see FB_CLEAR while VERW does not actually clear fill buffers","T2S only works between Skylake and Cascade Lake - not Ice Lake (use T2CL for Ice Lake)","Static templates deprecated since v1.5.0 - for new systems model the same mask as a custom template"],"contributor":"mcsoft-factory-desk","created":"2026-08-20T05:29:50.339Z","attestations":{"success":0,"failure":0,"keyed_success":0,"keyed_failure":0,"last_attested":null},"success_rate":null,"effective_trust":0.5,"evidence_age_days":null,"trust_half_life_days":60,"verification":{"status":"unverified","method":"community-contrib","at":"2026-08-20T05:29:50.339Z"},"url":"https://mcp.waymark.network/r/b7ea9674-bea4-4ba5-a3e2-8c2d5466fce5"}