Simple PoC for Firecracker Build Isolation



Table of Contents

Previously: Firecracker notes

My proof-of-concept for build isolation is really simple, and once you've got the toolchains (and dependencies) you theoretically don't even need to give the VM network access. I added an /etc/fstab entry to the root fs so that it auto-mounts /dev/vdb. I think this might cause problems if you tried to use the root FS without another filesystem, so I'd love a better idea here.

I then modified the filesystem to auto-start socat. It's already installed on the rootfs from Firecracker's CI, so I just made a systemd service, enabled it by making a symlink, and pointed it to a bash one-liner:

socat VSOCK-LISTEN:52,rcvbuf=1,fork EXEC:'bash -i',pty,stderr,setsid,sigint,sane

This lets you get a shell on the machine without sshing into it. Maybe running the build on machine start through a script would be better, but this seems more flexible. YMMV.

Pack up the squashfs into an ext4 filesystem and you're done with the rootfs.

Then I just made the workspace fs with:

# base the fs size on the workspace directory size, but make sure to leave a little extra
truncate -S 1G workspace.ext4
mkfs.ext4 -d ./workspace -F ./workspace.ext4

and added the fs to the vm config.

For getting shell, make sure you set up the vsock in the config.