blog

Blog — page 24 of 38

·9 min read

Merging and Inspecting Firecracker Snapshots: snapshot-editor and the Rebase Workflow

Taking a snapshot is the easy part. A diff snapshot is a note that says 'these pages moved' — small, fast, and completely useless on its own. This is the operational guide to what you do with the files afterwards: rebasing, inspecting, compacting, and not deleting the one artifact a thousand others depend on.

firecrackersnapshotssnapshot-editor
Ajay Kumar
·9 min read

User namespaces, explained for sandboxing: what root-in-a-namespace actually buys you

A user namespace lets a process be uid 0 inside while being a nobody outside. It's the primitive behind rootless containers and it's genuinely great. It is also not a boundary: root inside the namespace is a job title, not a power.

user-namespaceslinux-kernelisolation
Ajay Kumar
·10 min read

Best Code-Execution Sandbox APIs for Go AI Agents in 2026

You're building an agent in Go, and every sandbox vendor's docs open with Python and TypeScript. This is the buyer's checklist for the person who's going to be reading the REST reference instead — plus how to wrap any sandbox API in a Go client that doesn't embarrass you.

comparisongolangai-agents
Ajay Kumar
·9 min read

Detonating malware in Firecracker microVMs

Malware detonation is the one workload where you voluntarily execute software written by someone who hates you. The boundary you pick is the whole product.

securitymalware-analysisfirecracker
Ajay Kumar
·9 min read

Sandboxing untrusted uploads: ImageMagick, ffmpeg, LibreOffice

Your thumbnailer has the same privileges as your billing code, and only one of them was written to be fed hostile bytes. The per-upload microVM pattern, end to end.

securitysandboxmicrovm
Ajay Kumar
·10 min read

Chaos Engineering Inside microVMs: Fault Injection Without the Blast Radius

Real chaos experiments need real kernel knobs. A container shares the host kernel, so you either fake the fault at the application layer or you inject it into everyone on the box. A microVM lets you be genuinely nasty to exactly one guest.

chaos-engineeringfault-injectionmicrovm
Ajay Kumar
·10 min read

Running CTF challenges and cyber ranges on microVMs

You have invited three hundred strangers to attack your infrastructure and told them there are points in it. Your isolation boundary cannot be a strongly worded rules page.

ctfcyber-rangesecurity-training
Ajay Kumar
·10 min read

The Firecracker REST API: booting a microVM by hand with curl

Firecracker has no CLI for humans. It has a REST API on a Unix socket, and the fastest way to understand the whole design is to drive it yourself with curl until a kernel prints to your terminal.

firecrackermicrovmapi
Ajay Kumar
·9 min read

Firecracker boot_args, argument by argument

Everyone copies the same magic `boot_args` string from the Firecracker docs and never reads it. It's a short, unusually honest description of what a microVM is — and what it has decided not to be.

firecrackerkernelmicrovm
Ajay Kumar
·9 min read

Snapshot, Restore, and the Connections You Left Open

A snapshot captures the guest's entire opinion about its network: socket table, sequence numbers, retransmit timers, ARP cache, TLS sessions. The one participant never consulted is the machine on the other end of every one of those connections.

snapshotsnetworkingfirecracker
Ajay Kumar
·10 min read

VM exits: the actual currency of virtualization overhead

"Virtualization overhead is about N percent" is a meaningless sentence. The unit that actually costs you something is the VM exit — and how many you burn depends entirely on what your guest is doing.

kvmvirtualizationperformance
Ajay Kumar
·9 min read

Firecracker vs Firejail: confining apps vs containing strangers

Firejail is a genuinely good tool for confining the browser you installed on purpose. It is a different question entirely from containing code a language model wrote thirty seconds ago — and the difference is whose kernel gets attacked.

firecrackerfirejailsandbox
Ajay Kumar
·10 min read

The Best Code Execution Sandboxes for Education Platforms in 2026

Coding courses have a workload nobody else has: nothing happens for six days, then four hundred submissions land in nine minutes, and at least one of them is a fork bomb. Here's how the options actually compare.

comparisoneducationautograder
Ajay Kumar
·10 min read

Best Remote Browser Isolation Platforms (2026)

RBI used to be about protecting a human from a drive-by exploit. In 2026 it's also about protecting you from your own agent — which will click things no human would, on a page that is actively trying to talk to it.

browser-isolationsecurityai-agents
Ajay Kumar
·9 min read

cgroups v2 Explained for Sandboxing Untrusted Code

cgroups v2 decides how much a process can consume. It has nothing to say about what that process can reach. If you're running AI-generated code, you need to know exactly where that line falls.

cgroupslinuxisolation
Ajay Kumar
·9 min read

Firecracker Shutdown and Reboot Semantics, Explained

There is no power button. A guest reboot doesn't reboot. And the dead VM is never the problem — the tap device, netns, chroot, and CoW clone it left behind are.

firecrackermicrovminternals
Ajay Kumar
·9 min read

Firecracker vs Multipass: a human's VM vs a program's VM

Both hand you "a quick Ubuntu VM," which is why they get compared. But one is built for a developer with a terminal and one is built for an orchestrator with an API — and on a Mac they're complements, not rivals.

firecrackermultipasscomparison
Ajay Kumar
·9 min read

Firecracker vs WebContainers: where should untrusted code run?

One runs code inside the user's browser tab and costs you nothing. The other runs a real guest kernel on a machine you pay for. The choice comes down to two questions: does the code need real Linux, and is there a human browser in the loop?

webcontainersfirecrackercomparison
Ajay Kumar
·9 min read

Letting an AI Agent Run Integration Tests Against Real APIs

Unit tests are safe to run anywhere. Integration tests need real credentials and real egress — exactly the two capabilities you least want to hand a model on a shared host. Here's the shape that works.

ai-agentstestingmicrovm
Ajay Kumar
·9 min read

Running User-Generated Game Mods in Isolated microVMs

A mod is arbitrary code from a stranger that you execute on your infrastructure. "We removed the io library" is not a security boundary — a guest kernel is.

gamingmoddingmicrovm
Ajay Kumar
·8 min read

Per-Tenant Workflow Workers in Isolated microVMs

A shared worker pool runs every tenant's activity code in one process on one kernel. One runaway retry loop starves everyone, and "we run customer code in a thread with a timeout" is not a security model.

workflowsmulti-tenantmicrovm
Ajay Kumar
·9 min read

Robotics Simulation and RL Rollouts in Isolated microVMs

Simulation is embarrassingly parallel and pathologically environment-sensitive. A baked microVM snapshot is the pinned sim environment — and a per-sandbox network namespace finally shuts ROS 2 discovery up.

roboticssimulationreinforcement-learning
Ajay Kumar
·11 min read

Running IoT and Embedded Firmware Emulation in Disposable MicroVMs

A firmware image is a filesystem, an init, and a stranger's opinion about what should happen at boot. You are going to run all three. Do it somewhere you can delete.

firmware-analysisiot-securityemulation
Ajay Kumar
·10 min read

Isolating Per-Tenant Geospatial Processing Jobs in MicroVMs

A customer uploads a shapefile and your worker decides, based on those bytes, which of GDAL's hundred-plus drivers to run. That's not a data pipeline — that's attacker-controlled parser dispatch with a database credential in the room.

geospatialgdalmulti-tenant
Ajay Kumar