blog

Blog — page 11 of 38

·9 min read

Running npm install in a MicroVM: Dependency Installation Is Arbitrary Code Execution

A postinstall script is an unsigned contract you agreed to by typing eight characters. Here is how to run dependency installation in a disposable microVM — and how snapshot forking makes it cheaper than what you do today.

supply-chain-securitymicroVMsCI/CD
Ajay Kumar
·10 min read

Rendering user-authored templates safely: SSTI and the microVM fix

You shipped a text formatter so customers could edit their own emails. Depending on the engine, you may also have shipped them a REPL on your application server.

microvmsecuritymulti-tenant
Ajay Kumar
·9 min read

The Custom Code Step: Isolating User Code in a Low-Code Builder

The "Run JavaScript" block is where a no-code product admits it is a code product with a very good editor. Here is how to run it without betting the platform on it.

low-codemicrovmisolation
Ajay Kumar
·10 min read

How to profile code running in a sandbox

Attaching a profiler to a pod is muscle memory. Inside a microVM, half of that muscle memory works and the other half quietly wastes your afternoon.

profilingperformancedebugging
Ajay Kumar
·10 min read

How to build a multi-tenant audit log your customers' auditors will accept

Every enterprise deal asks for an audit log. Most teams bolt one on in a sprint, discover it is really just their application logs wearing a suit, and then get to build it twice.

audit-logmulti-tenancysecurity
Ajay Kumar
·9 min read

SLOs and error budgets for a code-execution platform

The standard SRE examples assume a long-lived request-serving service. A platform that boots machines on demand breaks all of them. Here's the version that survives contact with a sandbox fleet.

sreobservabilityoperations
Ajay Kumar
·9 min read

How to cut your sandbox compute bill: an engineer's playbook

The per-second rate is almost never why your ephemeral compute bill is high. Idle time, forgotten resources and repeated setup work are. Here is the order I attack them in.

cost-optimizationai-sandboxoperations
Ajay Kumar
·10 min read

Docker-in-Docker vs microVMs for CI builds

Your CI runners are containers and your jobs need to build images. Every answer to that trades privilege for convenience — here's the honest accounting of all four.

CI/CDdockersecurity
Ajay Kumar
·10 min read

PandaStack vs Coder

These two products are shopped against each other constantly and compete almost never. One gives a person a machine for the week; the other gives a program a machine for four seconds. Naming that split is most of the decision.

comparisondev-environmentscoder
Ajay Kumar
·10 min read

The best self-hosted FaaS platforms in 2026

"Self-hosted serverless" is a phrase that has to fight itself — you didn't eliminate the servers, you adopted them. Here's the honest field of open-source FaaS platforms, and the container-isolation question most of these lists skip.

serverlessfaasself-hosted
Ajay Kumar
·10 min read

A Model File Is a Program: Per-Tenant Serving Isolation

You let customers upload their own models and you serve inference for them. Congratulations: you built a remote code execution endpoint with a friendly onboarding flow. Here's the real threat model and the isolation shape that survives it.

ml-servingsecuritymulti-tenancy
Ajay Kumar
·10 min read

Your Tenant Wrote a Regex. The Regex Is the Malware.

Your customer didn't ship malware, they shipped a pattern with a nested quantifier — and one long stack trace turns it into a fleet-wide outage. The failure modes of tenant-supplied log parsing, and the validation path that catches them before production does.

logsobservabilitymulti-tenant
Ajay Kumar
·10 min read

Your Support Agent Has a Shell and Your Admin Token

The ticket body is untrusted input from a stranger, and you are feeding it to a model that has a shell and your admin API token. Here is the threat model and the per-ticket microVM shape that contains it.

ai-agentssecurityprompt-injection
Ajay Kumar
·10 min read

Your Scale-to-Zero App Never Sleeps, and Bots Are Why

An app set to sleep after 15 idle minutes billed like an always-on server for a month. Nobody was using it — except an uptime monitor, four scanners, and our own health check. Here's the two-predicate classifier that fixed it.

scale-to-zeroapp-hostingbot-traffic
Ajay Kumar
·10 min read

Lease vs Heartbeat: How a Fleet Decides a Node Is Dead

You cannot tell a dead node from a slow network — you can only choose which way to be wrong. Heartbeats, leases, ownership columns, and the negative-caching bug that 503s a perfectly healthy fleet.

distributed-systemsschedulerreliability
Ajay Kumar
·10 min read

PID namespaces and process isolation, explained: what CLONE_NEWPID actually gives you

A PID namespace gives you a private set of process numbers and a process the kernel treats as init. It is excellent plumbing and it is not a security boundary, and almost every bug you will hit lives in the gap between those two sentences.

pid-namespaceslinux-kernelprocess-isolation
Ajay Kumar
·9 min read

Container Escape CVEs, by Class: What the Pattern Tells You

Container escapes aren't a list of unlucky bugs — they're four recurring shapes, plus one category that will never get a CVE because it's working as designed.

securitycontainersisolation
Ajay Kumar
·10 min read

tmpfs in a microVM: The Filesystem That Eats Your RAM

Writing a gigabyte into /tmp inside a microVM does not consume disk. It consumes the guest RAM your process was counting on — and if you snapshot that VM, the gigabyte gets cloned into every copy.

firecrackerlinuxmicrovm
Ajay Kumar
·10 min read

PandaStack vs Google Cloud Run: Honest Head-to-Head

Cloud Run runs your container and owns its lifecycle. PandaStack hands you a microVM and lets you hold it. Most teams should use Cloud Run — this is about the narrow set who shouldn't.

comparisongoogle-cloud-runfirecracker
Ajay Kumar
·11 min read

Northflank vs Railway: Control or Momentum?

Both let you ship a repo without operating a cluster, and both are good at it. The choice is really about how much control you want versus how fast you want to be productive — plus the lock-in question everyone skips.

comparisonnorthflankrailway
Ajay Kumar
·9 min read

How a Sandbox Scheduler Decides Where Your VM Lands

Every sandbox platform has a scheduler picking which machine your VM lands on. Here's the scoring function we actually run, the staleness window that made five simultaneous creates pile onto one host, and why the fix wasn't smarter scoring.

schedulerinternalsmicrovm
Ajay Kumar
·9 min read

How Many Sandboxes Fit on One Machine?

Everyone wants a number. The real answer depends on which resource binds first — and on most microVM fleets, the host memory metric you'd naturally scale on is actively lying to you.

capacityinternalsmicrovm
Ajay Kumar
·10 min read

Where Scale-to-Zero Wake Time Actually Goes

Scale-to-zero sounds like a hypervisor problem. When we instrumented a real wake, the VM restore was 1.4 seconds of 14 — the rest was our own orchestration doing careful things in the wrong order.

scale-to-zeroperformanceinternals
Ajay Kumar
·9 min read

How to Vet a Code Execution Vendor's Security

If your AI agent runs model-generated code, you've outsourced a security boundary. Here are the questions worth asking a vendor, why SOC 2 answers almost none of them, and what the honest answers sound like.

securitycomplianceprocurement
Ajay Kumar