See how Netlify rebuilt Edge Functions on MicroVMs to deliver lower latency, greater reliability, and faster log delivery.

112 points•jbott•about 7 hours ago•40 comments•

40 comments

Normal_gaussianabout 4 hours ago
I've been using SlicerVM extensively - which is Firecracker MicroVMs for the regular person (and for the irregular with their platform offering) - to run local 'edge' style workloads locally and securly. Agents, local dev CI, etc. It slotted in and replaced my proxmox vm orchestrator, and now I have secure and and fast vms on my laptop wherever I go. It also supports dockerfile style builds if you're wanting a security upgrade from containers (which, you should if you're using agents).

Honestly, while I see firecracker replacing docker on the horizon I don't see firecracker replacing v8 isolates for most edge function execution. Firstly, this article's scenario is a bit unusual in that they were using someone else's isolates - so adding on a few hops; secondly isolates running JS/TS can be statically analyzed quite well, and at scale looking historically for issues and exploits, in many edge compute scenarios this is quite desirable. MicroVMs can have an awful lot more flexibility so to get the same benefit you have to really lock down what is available - the trade-offs for mid-size companies seems to benefit isolates. Obviously netlify is more than big enough and relies heavily on this that it leans in their favour.

jst1fthsdysabout 4 hours ago
25 USD/m to run a daemon on my own hardware. Yikes.
binsquareabout 3 hours ago
That seems off to me as well.

Fwiw, you can run this instead free and open source: https://github.com/smol-machines/smolvm

Disclaimer: Am author.

QGQBGdeZREunxLeabout 3 hours ago
I think Alex learned his lesson offering a free version running OpenFaaS.
innocent_nameabout 3 hours ago
https://unikraft.com/blog/netlify-edge-functions and https://slicervm.com/ both using the lookalike slop design template made me to believe it was a shadowy unikraft project lol.
nderjungabout 5 hours ago
Alex from Unikraft here! Happy to answer any questions about the microVM part of the story from our side.

We also did a couple of technical write ups if you're interested:

- https://unikraft.com/blog/netlify-edge-functions

- https://unikraft.com/customer-stories/edge-functions-netlify

nchmyabout 6 hours ago
I'm having trouble understanding/believing this, given that Cloudflare Workers are also v8 isolates and run vastly faster than the 25-40ms that netlify says their isolates took...
phickeyabout 5 hours ago
from the article: "With our old infrastructure it went out over the internet, ran the edge function, and came back to us to pass on. With the new compute platform, the request is forwarded to a compute node within our network."

As far as I know, Cloudflare Workers have always executed within Cloudflare's network, not gone out to the internet and executed elsewhere (which I read as being in a hyperscaler cloud).

irq-1about 5 hours ago
> In the past, requests went out to a hosted execution service. Today, they run on MicroVMs inside our own edge network

The isolates were not being run at the edge.

bobfunkabout 5 hours ago
They were running on the edge, and in the same datacenters but by another provider.
yencabulatorabout 2 hours ago
> In the past, requests went out to a hosted execution service. Today, they run on MicroVMs inside our own edge network — roughly 5x faster at the median.

So, the execution itself might now be slower as far as we know, they just eliminated some networking from the mix? Misleading.

jedbergabout 4 hours ago
The next time you want to curse AWS, remember they gave us Firecracker, one of the best microvm technologies out there, and the basis of at least a few non-AWS products out there (this one being the newest entry to the list).

Read the full thread on Hacker News →

Related stories