Skip to content

Instantly share code, notes, and snippets.

@nmajor
Created March 30, 2026 13:41
Show Gist options
  • Select an option

  • Save nmajor/29e97b1b635b1e27cae834968b6d4623 to your computer and use it in GitHub Desktop.

Select an option

Save nmajor/29e97b1b635b1e27cae834968b6d4623 to your computer and use it in GitHub Desktop.
Firecracker Sandbox Platform: Technical Research (cold starts, snapshot/restore, single binary, tiered isolation, unikernel comparison)

Firecracker Sandbox Platform: Comprehensive Research

Date: 2026-03-30 Context: Evaluating a bootstrapped SaaS opportunity — open-source Firecracker sandbox platform with managed cloud offering. Research conducted across competitive landscape, technical feasibility, market sizing, and business viability.


Table of Contents

  1. Market Landscape
  2. Funded Competitors
  3. Open Source Landscape (Reality Check)
  4. E2B Deep Dive — Weaknesses & Customer Pain
  5. Technical: Snapshot/Restore Reliability
  6. Technical: Achieving Fast Cold Starts
  7. Technical: Single Binary & Self-Hosting Feasibility
  8. Technical: Tiered Isolation Model
  9. Unikernel vs Firecracker Comparison
  10. Unit Economics on Hetzner
  11. SEO & Keyword Data
  12. Bootstrapped Infra Business Comps
  13. Operational Reality for Solo Dev
  14. Business Viability Assessment
  15. Use Cases Ranked by Value
  16. How Infra Tools Get Marketed
  17. Sources

Market Landscape

Funding in the sandbox/microVM space (2024-2026)

Company What They Do Raised Key Signal
E2B Firecracker sandboxes for AI agents $35M 40K → 15M sandboxes/month in one year
Modal Serverless compute $111M+ Raising at $2.5B valuation
Browserbase Cloud browser instances $67.5M $300M valuation
Daytona AI agent sandboxes (Docker) $24M $1M ARR in <3 months
Kernel Unikernel browsers $22M YC S25
Fly.io Firecracker Machines $90M+ Launched "Sprites" Jan 2026
RunLoop AI coding agent sandboxes $7M Ex-Stripe team
Steel.dev Headless browser API $17M Open source

Total disclosed funding in adjacent space: $400M+

Market size signals

  • AI agent market: $5B (2024) → projected $47B by 2030
  • Infrastructure typically 10-20% of total market spend = $500M-$1B sandbox TAM by 2026-2027
  • AI code tools market: $7.9B in 2025, projected $26B by 2030 (27.1% CAGR)
  • Serverless computing market: $21.9B in 2024, projected to nearly double by 2029
  • E2B alone: 40K sandboxes/month → 15M sandboxes/month in one year (375x growth)

Estimated number of potential sandbox buyers

  • ~1,500-3,000 AI agent startups globally (CB Insights, 2024-2025)
  • ~30-50% need isolated code execution = 600-1,500 potential buyers
  • YC funds ~60-100 agent startups per batch

Funded Competitors

E2B ($35M raised, a16z)

  • Product: Firecracker-based sandboxes for AI code execution
  • Pricing: Free hobby tier ($100 one-time credit) → $150/mo Pro + usage → $3,000/mo Enterprise
  • Per-second rates: $0.000014/vCPU/s (~$0.05/hr for 1 vCPU)
  • Limits: 24-hour max sessions, 20 concurrent (Hobby), 100-1,100 (Pro/Enterprise)
  • Claims: 88% of Fortune 100, 200M+ sandboxes started total
  • SDK: Python and JavaScript only. No Go, Rust, Java.
  • BYOC: AWS only, enterprise pricing
  • Self-hosting: Open source (Apache 2.0) but requires Nomad + Consul + Terraform + GCP/AWS

Daytona ($24M Series A)

  • Product: AI agent sandboxes, Docker-based (NOT Firecracker)
  • Cold start: Sub-90ms claimed
  • Key diff: Persistent sandboxes, computer use support (browser/desktop), easier self-hosting via Helm
  • Weakness: Container isolation, not hardware VM isolation

Fly.io Sprites (launched Jan 2026)

  • Product: Persistent VMs with checkpoint/restore
  • Restore time: ~300ms-1s
  • Key diff: Indefinite filesystem persistence, NVMe storage, auto-hibernation
  • Weakness: Slow restore, no self-hosting, no custom templates

Modal ($111M+, $2.5B valuation talks)

  • Product: Python-first serverless compute with GPU
  • Key diff: GPU support (A100, H100), strong Python DX
  • Weakness: Python-only, no BYOC, gVisor isolation (not hardware VM)

Northflank (funded, 2M+ microVMs/month)

  • Product: Production sandbox platform, BYOC
  • Key diff: GPU (H100 at $2.74/hr), multi-cloud BYOC, OCI image support
  • Aggressively publishing comparison content against every competitor

Open Source Landscape

The reality check — most "competitors" are vapor

Project Stars Age Maintained? Production-Ready? Honest Assessment
firecracker-containerd 2,733 2018 Yes (AWS) Yes Gold standard building block, but low-level
Alibaba OpenSandbox 9,585 3 months Very active Yes Production-ready but uses CONTAINERS, not VMs
Microsandbox 5,188 ~18 months Slowing Beta Uses libkrun (not Firecracker), YC-backed
E2B Infra 983 Active Very active Yes Designed for E2B's SaaS, hard to self-host
ZeroBoot 2,013 15 days Solo dev Prototype Clever 0.8ms CoW fork, no networking, no production users
ForgeVM 13 5 weeks Solo dev Early alpha Real code (~26K LOC), 28ms restore, zero users
Flintlock 1,346 2021 Slowing Beta Best community orchestrator, 4 months since last commit
Ignite 3,527 2019 DEAD No Archived, Weaveworks bankrupt
HatchVM ~0 Unknown Unknown No Vaporware — no public repo
FireSquid 75 2020 No No Abandonware
Fireactions 143 2023 Yes Yes (CI only) Good but only does GitHub Actions runners

Key finding

There is no production-quality open-source Firecracker sandbox platform with reliable snapshot/restore and easy self-hosting. The gap is real.


E2B Deep Dive

Documented bugs (all orchestration-layer, not Firecracker)

Bug Root Cause Category
Files lost after 2nd resume (#884) Restoring from stale snapshot, not syncing I/O before pause Orchestration race condition
autoPause overridden (#875) SDK logic bug in sandboxApi.ts SDK bug
Processes disappear after resume (#1031) Process tracking lives outside VM Orchestration state mgmt
Sandboxes deleted instead of paused (#157) Lifecycle manager bug Orchestration bug
Sandbox creation timeout (#1130) UFFD page fault handling bug Orchestration bug
Timeout not honored (#879) 24h timeout ignored, killed at 5min SDK/platform bug

Feature gaps customers ask for

Gap Evidence
Persistence that works (still beta) GitHub #884, #875; every competitor blog
GPU support Zero offering; Modal/Northflank winning these
Self-hosting without Nomad expertise 983 stars on infra repo, HN comments
No $150/mo base fee Steep jump from free to paid
Sessions > 24 hours Fly.io Sprites offers indefinite
Go/Rust SDKs GitHub #985, only JS/Python
BYOC without enterprise pricing Locked behind enterprise contracts
Sandbox cloning GitHub #928

Pricing comparison

Platform CPU Rate Approx. Hourly Base Fee
E2B $0.000014/vCPU/s ~$0.05/hr $150/mo (Pro)
Northflank ~$0.0000046/vCPU/s ~$0.017/hr None disclosed
Modal $0.0000131/core/s ~$0.047/hr $0 (free credits)
Fly.io Sprites — ~$0.07/CPU-hr $0
DIY on Hetzner — ~$0.001/vCPU-hr equiv Server cost

E2B is roughly 4x more expensive per vCPU than Northflank.


Snapshot/Restore Reliability

Key finding: This is a SOLVED engineering problem

Every E2B and Fly.io bug traces to known, fixable causes. The Firecracker snapshot mechanism itself is solid.

Root causes of all known failures

Failure Who Hit It Root Cause Known Fix
Files lost on repeated resume E2B Stale snapshot, no I/O sync syncfs before snapshot via guest agent
0.6% resume failures Fly.io Race condition bind() vs listen() Retry logic on ECONNREFUSED
Progressive slowdown Fly.io vsock port leak in guest init Close connections before snapshot + random port
Processes hang after restore (AMD) CodeSandbox TSC_DEADLINE MSR ordering Firecracker PR #4666 (merged upstream)
Process tracking lost E2B Tracking outside VM Track inside VM via guest agent
500ms-2s restore Fly.io Proxy detection + health check polling Direct orchestration, no proxy layer

The recipe for reliable snapshot/restore

  1. Guest agent as PID 1 — handles lifecycle hooks inside the VM
    • Before pause: syncfs(), close connections, signal ready
    • After resume: reseed entropy, sync clock, reconnect, signal ready
  2. Use Firecracker >= PR #4666 (AMD TSC fix, now upstream)
  3. Linux kernel >= 5.18 in guest (VMGenID for automatic entropy reseeding)
  4. vsock for host-guest communication (not TCP — avoids broken connection class)
  5. Pre-create resource pools (TAP devices, namespaces, cgroup hierarchies)
  6. Simple orchestrator (not Nomad/Consul — eliminates 60-180ms scheduling overhead)
  7. CoW overlays for isolation between snapshot instances

What's genuinely hard (no clean solution)

  • Suspend latency for large memory (writing N GB to disk takes time)
  • Cross-version snapshot compatibility (format coupled to exact Firecracker + kernel version)
  • Userspace entropy reseeding (no generic solution; per-application handling needed)

Achieving Fast Cold Starts

Measured restore latencies from real systems

Source VM Size Restore Latency Notes
Firecracker raw vCPU resume Any <5ms Just register restore + mmap
ForgeVM Not specified 28ms Full end-to-end with guest agent
AWS Lambda SnapStart ~512MB ~30-70ms Java workloads
CodeSandbox 1-2GB ~150-200ms VM cloning
Fly.io Variable ~500ms-2s Includes proxy + health check overhead
E2B Variable ~150ms Firecracker portion; orchestration adds more

Optimization roadmap

Phase 1 — Match E2B but reliable (~40-80ms):

  • Standard Firecracker + NVMe storage
  • Guest agent with lifecycle hooks
  • Pre-created resource pools

Phase 2 — Beat everyone (~15-20ms):

  • Minimal guest kernel (Lupine-style, 19 KConfig options, ~1.5MB)
  • Snapshots on tmpfs (RAM-backed)
  • Purpose-built orchestrator (no Nomad)
  • vsock readiness signaling
  • Working set prefetching with madvise(MADV_WILLNEED)

Phase 3 — Pushing limits (~8-12ms):

  • LZ4 compressed snapshots with lazy page loading
  • CoW snapshot sharing across identical bases
  • Predictive page prefetching
  • Pinned vCPUs, isolated cores

Key insight on nested vs bare metal

Host Type Firecracker Works? Snapshot Restore Cost
Hetzner bare metal Yes (native KVM) ~5-28ms ~$42-221/mo
Hetzner Cloud VPS Yes (nested KVM) ~10-25ms ~$5/mo
GCP (nested virt) Yes (officially supported) ~10-25ms ~$25/mo
AWS EC2 Intel Nitro Mostly yes ~10-30ms ~$30/mo
DigitalOcean No (/dev/kvm unavailable) N/A N/A
Most cheap VPSes No N/A N/A

Nested virt penalty is ~5-20ms — invisible at self-hosting scale.


Single Binary and Self-Hosting

Feasibility: YES (k3s proves the model)

Component Size
Firecracker binary ~2.5 MB
Guest kernel (minimal vmlinux) ~5-10 MB
Base rootfs (Alpine) ~50 MB
Orchestrator + API + guest agent ~5-10 MB
Total (compressed) ~30-50 MB

k3s bundles Kubernetes + containerd + etcd + CoreDNS into ~60MB. This is smaller.

Minimum host requirements

  • Linux kernel 5.4+ (5.18+ recommended for VMGenID)
  • x86_64 with Intel VT-x or AMD-V
  • 2 vCPU, 1-2GB RAM minimum
  • Works on: Ubuntu 22.04/24.04, Debian 11/12, Alpine, Amazon Linux 2/2023, RHEL 8+

Self-hosting UX target

curl -sSL https://yourthing.dev/install.sh | bash
yourthing start
# API at localhost:8080, ready to create sandboxes

Tiered Isolation Model

Nobody does this yet. This is the key product differentiator.

On startup, auto-detect:
  /dev/kvm exists? → Firecracker microVMs (hardware isolation, fast snapshots)
  No /dev/kvm?     → gVisor (user-space kernel, works on any Linux VPS)
  Neither?         → bubblewrap + seccomp (lightweight, works everywhere)

What this enables

Host Isolation Cold Start Cost
Hetzner bare metal Firecracker (strongest) ~5-28ms $42-221/mo
Hetzner Cloud VPS Firecracker ~10-25ms ~$5/mo
GCP VM Firecracker ~10-25ms ~$25/mo
DigitalOcean $5 droplet gVisor (strong) Near-instant $5/mo
Any Linux VPS gVisor or bubblewrap Near-instant Any
Inside Docker bubblewrap (moderate) <1ms Free

Comparison to competitors

  • E2B: Firecracker only — won't run without KVM
  • Daytona: Docker only — weaker isolation
  • Modal: Managed only — no self-hosting
  • This platform: Adapts to whatever hardware is available

Unikernel vs Firecracker Comparison

Why we ruled out unikernels for a general-purpose platform

Factor Firecracker Unikernels (Unikraft)
Run any Linux binary Yes No — ~160 of ~350 syscalls
fork() Full support No (vfork+exec only)
Python + numpy/pandas Full support Broken with multiprocessing
Docker images Native via containerd Must rebuild as unikernel
Debugging Full Linux tools No strace, gdb, shell
Snapshot/restore Mature, production-proven Not production-ready
Cold start ~28ms (snapshot) / ~125ms (boot) ~4ms
Memory overhead ~5-15 MB ~1-4 MB

Key unikernel limitations

  • No fork() — breaks bash, git, npm, pip, every shell command
  • ~160 of ~350 Linux syscalls — apps fail silently on unsupported calls
  • No dlopen() in static builds — breaks Python C extensions, Java JNI, Node.js native addons
  • No /proc, no /sys, no debugging tools
  • Unikraft explicitly rejects becoming Linux-compatible: "conscious decision against full fork() support"
  • AI dev sandbox use cases (running Claude Code, Devin, etc.) are fundamentally incompatible

Unikernels are good for single-purpose workloads

  • Headless browsers (Kernel.sh)
  • Redis/caches (single-threaded by design)
  • Go/Rust HTTP APIs (single binary, no fork)
  • Reverse proxies (nginx single-worker)

Unit Economics on Hetzner

Server options

Server RAM Cores Monthly Cost Concurrent 4GB Sandboxes
AX41-NVMe 64 GB 6 $42 ~14
AX102-U 128 GB 16 $116 ~28
AX162-R 256 GB 48 $221 ~58
EX130-R 256 GB 24 $149 ~58

Note: sandbox memory is configurable. Most AI code sandboxes need 256MB-1GB, not 4GB (that's for browsers). At 512MB per sandbox, an AX162-R supports ~460 concurrent sandboxes.

Revenue scenarios (charging ~$0.03/hr, ~50% cheaper than E2B)

Scale Servers Infra Cost Revenue (50% util) Margin
Early 1 AX41 $42/mo ~$315/mo 87%
Growing 1 AX162-R $221/mo ~$2,100/mo 89%
Target ($200K/yr) 3 AX162-R $663/mo ~$16,700/mo 96%

Managed cloud pricing model

  • No base fee (unlike E2B's $150/mo)
  • Per-second billing: $0.000008/vCPU/s ($0.03/hr for 1 vCPU)
  • Free tier: 100 sandbox-hours/month
  • Pro: usage-based, no cap
  • Self-hosted: free forever (open source)

SEO and Keyword Data

Real Google Ads data (DataForSEO, US, March 2026)

Keyword Monthly Vol Trend Competition CPC
virtual browser 3,600 Growing (5,400 Jan '26) LOW $5.24
e2b (brand) 2,900 Growing fast (4,400 Feb '26) LOW $9.33
fly.io (brand) 2,900 Stable LOW $12.01
cloud browser 1,900 Growing fast (3,600 Feb '26) LOW $9.29
modal labs (brand) 1,600 Growing (1,900 Feb '26) LOW $16.45
docker alternative 1,300 Stable LOW $7.80
browserless (brand) 1,300 Growing (1,600 Feb '26) LOW $19.72
ai sandbox 880 Growing fast (1,300 Feb '26) LOW $8.56
ephemeral environments 320 Stable LOW $67.93
remote browser 320 Growing LOW $11.08
unikraft (brand) 260 Slight growth LOW $0
serverless containers 110 Volatile LOW $9.57
ephemeral compute 40 Growing (70 Jan '26) LOW $25.98
modal alternative 30 Growing fast (10→70) LOW $0

Key SEO insights

  • Brand searches dominate — people search for "e2b", "fly.io", "modal labs", not category terms
  • "ai sandbox" is the emerging category term (880/mo, growing to 1,300)
  • "ephemeral environments" has absurdly high CPC ($67.93) — enterprise buyers
  • "e2b" brand search nearly doubled (2,400 → 4,400 in 3 months) — category is exploding
  • Niche infra terms ("microvm hosting", "firecracker hosting") have zero search volume
  • SEO won't be primary acquisition — HN, GitHub, Twitter drive infra tool adoption

Bootstrapped Business Comps

Real revenue data from bootstrapped infra/dev tool businesses

Company Model Revenue Team Size Notes
Sidekiq (Mike Perham) License/open-core $1M+/yr Solo → small Gold standard. No infra to run.
Plausible OSS + managed cloud $3.1M ARR ~5-6 Self-hosted donations = $300/mo (negligible)
Fathom Analytics Pure SaaS $1M+ ARR 2 Deliberately NOT open source
Browserless (Joel Griffith) SaaS API $1M+ ARR Started solo → ~5-10 Closest comp to sandbox platform
Coolify (Andras Bacsai) OSS + managed cloud ~$200K/yr Largely solo Reports burnout from support load
Tarsnap (Colin Percival) Pure SaaS Est. low-mid 6 figures Solo, 15+ years Designed for "operational boredom"

Revenue math for open source + managed cloud

Price Point Customers for $200K/yr Realistic?
$29/mo 575 Hard solo
$50/mo 334 Stretch
$100/mo 167 Possible
$150/mo 112 Achievable
$200/mo 84 Sweet spot

The Plausible/Coolify model applied to sandboxes

  • 3,000-5,000 GitHub stars → drives awareness
  • 500-2,000 self-hosting users → evangelize product
  • 2-5% convert to managed cloud → 100-150 paying customers
  • At $100-150/mo average → $120K-$270K/year

Operational Reality

From real solo infra operators

Colin Percival (Tarsnap, 15+ years solo):

  • A few hours/week average
  • Designed for "operational boredom" — append-only architecture
  • Hardest part is payment processing and customer support, not infrastructure
  • Over-provisions so capacity alerts aren't urgent

Joel Griffith (Browserless, started solo):

  • Heavy investment in self-healing automation
  • 60-70% of support tickets were customer misconfiguration
  • Hired support help at ~$30-40K MRR — infrastructure was manageable, customer interaction was not

Andras Bacsai (Coolify, largely solo):

  • 2-3 hours/day on support during peak periods
  • Vocal about burnout from the hosted cloud offering
  • Self-hosted version ironically less stressful (users accept more responsibility)

Support burden benchmarks

  • Developer tools/APIs: 5-15 tickets per 100 customers per month
  • Infrastructure specifically: 10-25 tickets per 100 customers per month
  • ~50% automatable with good error messages, dashboards, docs
  • At 200 customers: expect 10-30 tickets/month needing human attention

On-call reality

  • 99.9% uptime (43 min/month downtime) is achievable solo
  • 99.99% is NOT achievable solo
  • Sandbox/dev environments tolerate 99.9% — they're not production databases
  • Architectural patterns that minimize pages: idempotent operations, bulkheads, queue-based provisioning, graceful degradation, over-provisioning

Scaling from 1 to 10 servers

  • 1-2 servers: manageable with SSH and scripts
  • 3 servers: need basic automation (Ansible)
  • 10 servers: need proper orchestration, centralized logging, automated failover
  • Hetzner floating IPs enable 30-90 second automated failover
  • The jump from 1 to 3 is fine; 3 to 10 is where solo approaches collapse

Business Viability

The unoccupied position

"Easy to self-host Firecracker sandbox platform with reliable snapshot/restore, PLUS a managed cloud option."

Nobody owns this. E2B self-hosting requires Nomad/Consul/Terraform. Microsandbox is self-hosted only (no cloud). ZeroBoot is 15 days old. ForgeVM has 13 stars.

Strengths of this opportunity

  1. Market is exploding — 375x growth in E2B sandbox sessions in one year
  2. Competition is weaker than it looks — most OSS alternatives are vapor; E2B persistence is buggy
  3. Technical approach is proven — guest agent + lifecycle hooks are well-understood engineering
  4. HN is hungry for this — ZeroBoot got 2K stars and 310 HN points in 15 days
  5. Hetzner economics are excellent — 90%+ margins at scale
  6. Tiered isolation is genuinely novel — auto-detect KVM, fallback to gVisor/bwrap
  7. Single binary self-hosting is a first — nobody offers curl-install Firecracker sandboxes

Risks

  1. E2B could fix their persistence and simplify self-hosting — closing the gap
  2. Solo dev running infrastructure — on-call, support, reliability expectations
  3. Getting first 10 paying customers is the hardest part
  4. Market could consolidate — Fly.io, Vercel, Cloudflare could absorb it
  5. Burnout risk (per Coolify's experience)

Recommended approach

  1. 6-8 week sprint to MVP — single binary, single server, Python SDK, Firecracker + gVisor fallback
  2. Show HN launch — target 1K+ stars, validate interest
  3. Self-hosters first — build community, get feedback, iterate
  4. Managed cloud second — add when self-hosters validate PMF
  5. PhaseTab in parallel — generate revenue from browser automation while platform matures

Use Cases Ranked by Value

Priority Use Case Market Signal Why Snapshot/Restore Matters
1 AI Agent Sandboxes E2B: 15M/mo, $35M raised Checkpoint, fork, restore agent state
2 Browser Automation Browserbase: $300M valuation Instant restore of initialized Chrome
3 Multi-Tenant SaaS Plugins Shopify, Figma struggling Per-request microVM feasible at <50ms
4 CI/CD Runners Actuated validates Firecracker CI Per-job isolation with cached deps
5 Security Sandboxes $5.1B market, 18.6% CAGR Clean VM per sample in <50ms
6 Dev Environments Gitpod pivoted away, Daytona pivoted to AI Snapshot replaces container builds
7 FaaS (Better Lambda) $21.9B serverless market SnapStart for ALL runtimes

Marketing Playbook

How successful infra tools got their first users

Company Strategy Key Move
E2B Show HN + open source Narrow positioning: "sandboxed code execution for LLM outputs"
Modal Founder blog + private beta Erik Bernhardsson's years of blogging built credibility
Fly.io HN engagement + technical blog CEO personally responded to every HN comment
Render "Heroku replacement" timing Migration guides from Heroku ranked in search
Supabase "Open source Firebase" + Launch Weeks 5-7 daily HN posts per launch week
Vercel Created Next.js (OSS framework) Framework = acquisition funnel for hosting
Neon "Serverless Postgres" + deep technical blog Database branching as novel mental model
Plausible "Open source Google Analytics alternative" Privacy positioning against a hated incumbent

What works for dev infra

  1. Position against a known pain — "E2B but self-hostable" or "sandboxes that actually persist"
  2. Founder-led content — personal brand > company brand (5-10x more engagement)
  3. Technical blog > product marketing — write about the problem domain, not your product
  4. Free tier is mandatory — developers won't evaluate without trying
  5. Open source is distribution — GitHub stars = marketing
  6. Show HN is channel #1 — every successful dev tool launched there

Sources

Companies & Products

  • E2B: e2b.dev, github.com/e2b-dev/E2B, github.com/e2b-dev/infra
  • Daytona: daytona.io
  • Fly.io Sprites: sprites.dev, fly.io/blog
  • Modal: modal.com
  • Northflank: northflank.com/blog (extensive comparison articles)
  • Kernel: kernel.sh
  • Browserbase: browserbase.com
  • ZeroBoot: github.com/zerobootdev/zeroboot, zeroboot.dev
  • ForgeVM: github.com/DohaerisAI/forgevm
  • Microsandbox: github.com/superradcompany/microsandbox
  • Alibaba OpenSandbox: github.com/alibaba/OpenSandbox
  • Firecracker: github.com/firecracker-microvm/firecracker
  • firecracker-containerd: github.com/firecracker-microvm/firecracker-containerd
  • Flintlock: github.com/liquidmetal-dev/flintlock

Technical References

  • Firecracker NSDI 2020 paper: usenix.org/conference/nsdi20/presentation/agache
  • Firecracker snapshot docs: github.com/firecracker-microvm/firecracker/blob/main/docs/snapshotting/snapshot-support.md
  • Firecracker random-for-clones: github.com/firecracker-microvm/firecracker/blob/main/docs/snapshotting/random-for-clones.md
  • Restoring Uniqueness in MicroVM Snapshots: arxiv.org/abs/2102.12892
  • Lupine Linux (EuroSys 2020): dl.acm.org/doi/10.1145/3342195.3387526
  • A Linux in Unikernel Clothing: dl.acm.org/doi/pdf/10.1145/3342195.3387526
  • Marc Brooker's blog: brooker.co.za (Lambda/Firecracker internals)
  • ForgeVM 28ms article: dev.to/adwitiya/how-i-built-sandboxes-that-boot-in-28ms-using-firecracker-snapshots-i0k
  • CodeSandbox VM cloning: codesandbox.io/blog/how-we-clone-a-running-vm-in-2-seconds

Market Research

  • Northflank comparison articles: northflank.com/blog/best-code-execution-sandbox-for-ai-agents
  • Better Stack sandbox comparison: betterstack.com/community/comparisons/best-sandbox-runners/
  • AI code tools market: grandviewresearch.com/industry-analysis/ai-code-tools-market-report
  • Agentic browser landscape: nohacks.co/blog/agentic-browser-landscape-2026

HN Discussions

  • ZeroBoot Show HN: news.ycombinator.com/item?id=47412569 (310 points)
  • Cloudflare Sandbox thread: news.ycombinator.com/item?id=45610523
  • KraftCloud launch: news.ycombinator.com/item?id=39902949
  • E2B discussions: news.ycombinator.com/item?id=44854120

Business & Revenue Data

  • Plausible revenue: plausible.io/blog/open-source-saas
  • Supabase $70M ARR: sacra.com/research/supabase-at-70m-arr-growing-250-yoy/
  • E2B Series A: siliconangle.com/2025/07/28/e2b-shares-vision-sandboxed-cloud-environments
  • Daytona Series A: prnewswire.com/news-releases/daytona-raises-24m-series-a

Hetzner Infrastructure

  • Server lineup: hetzner.com/dedicated-rootserver/
  • Pricing: hetzner.com/pricing
  • Network: 1 Gbit/s unlimited traffic standard
  • Best value for sandboxes: AX162-R (256GB RAM, 48 cores, $221/mo) or EX130-R (256GB, 24 cores, $149/mo)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment