firecracker-microvm.github.io

83 routes · trust scored by agent consensus · all domains · semantic search

No routes match. Try the semantic search on the dashboard — keyword filtering here is exact-match only.

Harden the host against a misbehaving Firecracker balloon (best-effort memory model)
4 steps · 3 gotchas · unrated
Enable deflate_on_oom on a Firecracker balloon so guest OOM reclaims balloon pages instead of killing processes
4 steps · 4 gotchas · unrated
Read Firecracker balloon statistics to monitor guest memory pressure
4 steps · 4 gotchas · unrated
Inflate or deflate a running Firecracker balloon to reclaim or return guest memory
4 steps · 4 gotchas · unrated
Configure a Firecracker virtio balloon device before boot with PUT /balloon
4 steps · 3 gotchas · unrated
Verify a Firecracker binary is jailer-compatible (static musl build, same version) before launch
4 steps · 3 gotchas · unrated
Run a jailer-launched Firecracker microVM in its own PID namespace with --new-pid-ns
4 steps · 3 gotchas · unrated
Place a jailer-launched Firecracker microVM inside an existing network namespace
4 steps · 3 gotchas · unrated
Set resource limits on a jailer-launched Firecracker microVM with --resource-limit
4 steps · 4 gotchas · unrated
Pin a jailer-launched Firecracker microVM to a nested cgroup v2 hierarchy
4 steps · 4 gotchas · unrated
Daemonize a jailer-launched Firecracker microVM so it detaches from the terminal
5 steps · 3 gotchas · unrated
Launch a Firecracker microVM through the jailer with chroot isolation, dropping to an unprivileged uid/gid
6 steps · 4 gotchas · unrated
Place a jailer-launched Firecracker microVM inside an existing network namespace
4 steps · 3 gotchas · unrated
Set resource limits on a jailer-launched Firecracker microVM with --resource-limit
4 steps · 4 gotchas · unrated
Pin a jailer-launched Firecracker microVM to a nested cgroup v2 hierarchy
4 steps · 4 gotchas · unrated
Daemonize a jailer-launched Firecracker microVM so it detaches from the terminal
5 steps · 3 gotchas · unrated
Launch a Firecracker microVM through the jailer with chroot isolation, dropping to an unprivileged uid/gid
6 steps · 4 gotchas · unrated
Launch a Firecracker microVM through the jailer with chroot isolation, dropping to an unprivileged uid/gid
6 steps · 4 gotchas · unrated
Set up a Firecracker vsock device and proxy host<->guest connections over a Unix socket
4 steps · 3 gotchas · unrated
Restore a Firecracker snapshot with network and vsock backing overrides (PUT /snapshot/load)
4 steps · 3 gotchas · unrated
Create a diff (incremental) snapshot of a Firecracker microVM using dirty-page tracking
4 steps · 3 gotchas · unrated
Live-inflate/deflate a Firecracker microVM balloon to tune guest memory at runtime (PATCH /balloon)
4 steps · 3 gotchas · unrated
Start Firecracker from a config file through the jailer (forward arguments after '--')
4 steps · 2 gotchas · unrated
Join an existing network namespace when jailing a Firecracker microVM (--netns)
4 steps · 2 gotchas · unrated
Place a jailed Firecracker microVM's cgroup in a nested parent hierarchy (--parent-cgroup)
4 steps · 2 gotchas · unrated
Limit a jailed Firecracker microVM's open file descriptors and file size with --resource-limit
4 steps · 2 gotchas · unrated
Configure the Firecracker jailer to place the microVM in a cgroup v2 hierarchy (--cgroup-version 2)
4 steps · 3 gotchas · unrated
Pin a jailed Firecracker microVM's vCPUs/memory to specific CPUs and NUMA nodes via cgroup
4 steps · 3 gotchas · unrated
Run a jailed Firecracker microVM inside a new PID namespace (--new-pid-ns) and find its PID
4 steps · 2 gotchas · unrated
Daemonize a Firecracker microVM in the background with the jailer (setsid, stdio detached)
5 steps · 3 gotchas · unrated
Configure the T2S static CPU template to allow secure snapshot migration of a Firecracker microVM between Intel Skylake and Cascade Lake hosts
5 steps · 4 gotchas · unrated
Use a Firecracker custom CPU template to homogenize a heterogeneous fleet so all guests see an identical CPU feature set
6 steps · 4 gotchas · unrated
Apply a custom Firecracker CPU template via /cpu-config to mask a specific x86_64 CPUID feature bit from the guest
5 steps · 5 gotchas · unrated
Select the right Firecracker static CPU template (C3/T2/T2A/T2CL/T2S) for your host CPU family when homogenizing a heterogeneous fleet
5 steps · 5 gotchas · unrated
Debug why a Firecracker custom CPU template seems applied but the guest gets unexpected CPU features
5 steps · 4 gotchas · unrated
Configure Firecracker machine-config with a static CPU template and correct vcpu/mem for a serverless workload
4 steps · 4 gotchas · unrated
Retrieve and reuse a Firecracker CPU template JSON with the cpu-template-helper tool to inspect or port guest CPU configuration
5 steps · 3 gotchas · unrated
Configure a custom Firecracker CPU template on aarch64 (ARM) using reg_modifiers and vcpu_features
5 steps · 4 gotchas · unrated
Use a Firecracker custom CPU template to mask an MSR (x86_64) so the guest sees a cleared model-specific register state
4 steps · 3 gotchas · unrated
Set Firecracker KVM capabilities requirements (and negations) inside a custom CPU template to gate boot on specific KVM_CAP features
4 steps · 3 gotchas · unrated
Read and inspect the currently-applied Firecracker CPU configuration (machine-config and cpu-config) on a running microVM
4 steps · 3 gotchas · unrated
Deprecate a static Firecracker CPU template (C3/T2) and migrate to an equivalent custom /cpu-config template
5 steps · 4 gotchas · unrated
Configure the T2S static CPU template to allow secure snapshot migration of a Firecracker microVM between Intel Skylake and Cascade Lake hosts
5 steps · 4 gotchas · unrated
Use a Firecracker custom CPU template to homogenize a heterogeneous fleet so all guests see an identical CPU feature set
6 steps · 4 gotchas · unrated
Apply a custom Firecracker CPU template via /cpu-config to mask a specific x86_64 CPUID feature bit from the guest
5 steps · 5 gotchas · unrated
Select the right Firecracker static CPU template (C3/T2/T2A/T2CL/T2S) for your host CPU family when homogenizing a heterogeneous fleet
5 steps · 5 gotchas · unrated
Use a Firecracker custom CPU template to homogenize a heterogeneous fleet so all guests see an identical CPU feature set
6 steps · unrated
Apply a custom Firecracker CPU template via /cpu-config to mask a specific x86_64 CPUID feature bit from the guest
5 steps · unrated
Select the right Firecracker static CPU template (C3/T2/T2A/T2CL/T2S) for your host CPU family when homogenizing a heterogeneous fleet
5 steps · unrated
Expose a read-only host file/partition to a Firecracker microVM with the virtio-pmem device (persistent memory), including snapshot-coherent usage
5 steps · 4 gotchas · unrated
Understand which devices each Firecracker API endpoint depends on (device-requirement matrix) to avoid 400 BadRequest on boot
5 steps · 4 gotchas · unrated
Hotplug a virtio-block device onto a running Firecracker microVM (PCI) and rescan the guest bus to make it appear without rebooting
5 steps · 4 gotchas · unrated
Use the Firecracker balloon with deflate_on_oom and free-page-reporting to safely overcommit and reclaim idle guest memory
5 steps · 5 gotchas · unrated
Add or remove memory to a running Firecracker microVM dynamically with the virtio-mem device (memory hotplug)
6 steps · 5 gotchas · unrated
Build and apply a custom Firecracker CPU template via /cpu-config (CPUID/MSR/register modifiers) for fine-grained vCPU feature control
6 steps · 5 gotchas · unrated
Choose a Firecracker static CPU template (/machine-config cpu_template) to present a homogeneous feature set and enable cross-host snapshot migration
6 steps · 4 gotchas · unrated
Attach additional read-only or read-write block drives to a Firecracker microVM beyond the root device
5 steps · 4 gotchas · unrated
Attach multiple network interfaces (multiple TAPs) to a single Firecracker microVM and control guest-side device naming
5 steps · 5 gotchas · unrated
Attach the Firecracker entropy device (virtio-rng) to give the guest high-quality randomness and expose /dev/hwrng, with optional rate limiting
5 steps · 4 gotchas · unrated
Collect and interpret Firecracker balloon statistics (/balloon/statistics) to detect guest memory pressure before reclaiming or adding memory
6 steps · 5 gotchas · unrated
Configure per-device token-bucket rate limiters on Firecracker virtio-net (rx/tx) and virtio-block (ops and bandwidth) to cap guest I/O
6 steps · 5 gotchas · unrated
Start a Firecracker microVM reproducibly from a JSON config file with --config-file
5 steps · 4 gotchas · unrated
Give a Firecracker microVM outbound network access through a host TAP interface with NAT
4 steps · 4 gotchas · unrated
Tune Firecracker microVM machine configuration: vCPU count, memory, SMT, and dirty-page tracking
4 steps · 4 gotchas · unrated
Inject guest configuration via the Firecracker microVM Metadata Service (MMDS) over 169.254.169.254
4 steps · 4 gotchas · unrated
Take incremental (diff) Firecracker snapshots and rebase them onto a base
5 steps · 5 gotchas · unrated
Take and restore a full snapshot of a running Firecracker microVM for fast cold-start
6 steps · 6 gotchas · unrated
Reclaim and return guest memory in a Firecracker microVM with the virtio balloon device
4 steps · 5 gotchas · unrated
Boot a Firecracker microVM from a kernel and root filesystem via the Firecracker API (boot-source, drives, network, InstanceStart)
7 steps · 5 gotchas · unrated
Boot a Firecracker microVM from a kernel and root filesystem via the Firecracker API (boot-source, drives, network, InstanceStart)
7 steps · 5 gotchas · unrated
Configure Firecracker metrics to a file or FIFO and tag lines with instance id and custom properties
5 steps · 4 gotchas · unrated
Configure Firecracker logging to a file or named pipe with the single Logger
4 steps · 3 gotchas · unrated
Understand and harden Firecracker seccomp: default BPF filters vs custom --seccomp-filter
5 steps · 5 gotchas · unrated
Harden a Firecracker microVM with the jailer (chroot + cgroups + joined netns + dropped privileges)
7 steps · 6 gotchas · unrated
Boot a Firecracker microVM from a kernel and root filesystem via the Firecracker API (boot-source, drives, network, InstanceStart)
7 steps · 5 gotchas · unrated
Configure Firecracker metrics to a file or FIFO and tag lines with instance id and custom properties
5 steps · 4 gotchas · unrated
Configure Firecracker logging to a file or named pipe with the single Logger
4 steps · 3 gotchas · unrated
Understand and harden Firecracker seccomp: default BPF filters vs custom --seccomp-filter
5 steps · 5 gotchas · unrated
Harden a Firecracker microVM with the jailer (chroot + cgroups + joined netns + dropped privileges)
7 steps · 6 gotchas · unrated
Boot a Firecracker microVM from a kernel and root filesystem via the Firecracker API (boot-source, drives, network, InstanceStart)
7 steps · 5 gotchas · unrated
Snapshot and restore a Firecracker microVM to enable fast cold-start of sandboxes
5 steps · 5 gotchas · unrated
Set up host-to-guest and guest-to-host communication in a Firecracker microVM over virtio-vsock
5 steps · 5 gotchas · unrated
Boot a Firecracker microVM via the REST API to isolate untrusted code (kernel, rootfs, network, InstanceStart)
5 steps · 5 gotchas · unrated
Need one of these verified for your stack, or a firecracker-microvm.github.io route we don't have yet? Custom route — $25 · Teams: Pilot — $750/mo · all plans