liquidmetal-dev/flintlock

Goflintlock.liquidmetal.dev
Linux

Lock, Stock, and Two Smoking MicroVMs. Create and manage the lifecycle of MicroVMs backed by containerd.

firecrackercnimicrovmocikvm
Croissance des étoiles
Étoiles
1.5k
Forks
72
Croissance hebdomadaire
+8
Issues
57
5001k
oct. 2021mai 2023janv. 2025sept. 2026
ArtefactsGo Modules
README

Flintlock - Create and manage the lifecycle of MicroVMs, backed by containerd.

GitHub Tests Go Reference GitHub release

What is flintlock?

:tada: This project was originally developed by Weaveworks but is now owned & run by the community. If you are interested in helping out please reach out.

Flintlock is a service for creating and managing the lifecycle of microVMs on a host machine. We support the Cloud Hypervisor and Firecracker VMMs.

The original use case for flintlock was to create microVMs on a bare-metal host where the microVMs will be used as nodes in a virtualized Kubernetes cluster. It is an essential part of Liquid Metal and can be orchestrated by Cluster API Provider Microvm.

However, its useful for many other use cases where lightweight virtualization is required (e.g. isolated workloads, pipelines).

Features

Using API requests (via gRPC or HTTP):

  • Create and delete microVMs
  • Manage the lifecycle of microVMs (i.e. start, stop, pause)
  • Configure microVM metadata via cloud-init, ignition etc
  • Use OCI images for microVM volumes, kernel and initrd
  • Expose microVM metrics for collection by Prometheus
  • (coming soon) Use CNI to configure the network for the microVMs

Documentation

See our getting started with flintlock tutorial.

Contributing

Contributions are welcome. Please read the CONTRIBUTING.md and our Code Of Conduct.

You can reach out to the maintainers and other contributors using the #liquidmetal channel on the CNCF slack.

Other interesting resources include:

Getting Help

If you have any questions about, feedback for or problems with flintlock:

Your feedback is always welcome!

Compatibility

The table below shows you which versions of Firecracker are compatible with Flintlock:

Flintlock Firecracker Cloud Hypervisor
v0.9.x Official v1.11+ v41.0
v0.8.x Official v1.10+ v41.0
v0.7.0 Official v1.10+ v41.0
v0.6.0 Official v1.0+ or v1.0.0-macvtap v26.0
v0.5.0 Official v1.0+ or v1.0.0-macvtap v26.0
v0.4.0 Official v1.0+ or v1.0.0-macvtap Not Supported
v0.3.0 Official v1.0+ or v1.0.0-macvtap Not Supported
<= v0.2.0 <= v0.25.2-macvtap Not Supported
<= v0.1.0-alpha.6 <= v0.25.2-macvtap Not Supported
v0.1.0-alpha.7 Do not use Not Supported
v0.1.0-alpha.8 <= v0.25.2-macvtap Not Supported

NOTE: we no longer support using the Weaveworks fork (with macvtap) of Firecracker. If you want macvtap then please use Cloud Hypervisor as the vm provider.

License

MPL-2.0 License

Acknowledgements

The biggest acknowledgement goes to @Weaveworks who where pioneers in the early Kubernetes world and produced some fantastic open source that lives on despite the demise of the company. A big thank you to the company and everyone that worked there. It was the engineers at Weaveworks that originally created Liquid Metal. RIP Weaveworks.

Dépôts similaires
kata-containers/kata-containers

Kata Containers is an open source project and community working to build a standard implementation of lightweight Virtual Machines (VMs) that feel and perform like containers, but provide the workload isolation and security advantages of VMs. https://katacontainers.io/

Rustcrates.ioApache License 2.0kvmvirtualization
8.7k1.5k
weaveworks/ignite

Ignite a Firecracker microVM

GoGo ModulesApache License 2.0firecrackerkvm
ignite.readthedocs.org
3.5k233
arcboxlabs/arcbox

Run AI agents on real and isolated machines — own kernel, filesystem, and network — with <100ms boot. Local first, OCI compatible, pure Rust.

Rustcrates.ioApache License 2.0ai-agentscomputer-use
arcbox.dev
3k97
firecracker-microvm/firecracker-containerd

firecracker-containerd enables containerd to manage containers as Firecracker microVMs

GoGo ModulesApache License 2.0awscontainerd
2.9k245
microvm-nix/microvm.nix

NixOS MicroVMs

NixMIT Licensenixnixos
microvm-nix.github.io/microvm.nix/
2.9k228
zerobootdev/zeroboot

Sub-millisecond VM sandboxes for AI agents via copy-on-write forking

Rustcrates.ioApache License 2.0ai-agentscode-execution
zeroboot.dev
2.4k108
e2b-dev/infra

Infrastructure that's powering E2B Cloud.

GoGo ModulesApache License 2.0ai-agentscode-interpreter
e2b.dev
1.4k403
blst-security/cherrybomb

Stop half-done APIs! Cherrybomb is a CLI tool that helps you avoid undefined user behaviour by auditing your API specifications, validating them and running API security tests.

Rustcrates.iotutorialApache License 2.0blstfirecracker
1.2k84