mirror of
https://github.com/joelhooks/joelclaw.git
synced 2026-09-19 01:24:04 +08:00
cf55d75613
Fundamental fix: previous execInMicroVm used a poll-based protocol where host wrote to a shared directory and polled for results. But Firecracker uses virtio-block devices (not shared directories), so host and guest can't simultaneously access the same filesystem without page cache issues. New model (Lambda-style): 1. Host creates workspace ext4 image (64MB) 2. Host loop-mounts it, writes command.sh + request.json, unmounts 3. Host boots Firecracker VM with workspace as /dev/vdb 4. Guest-runner (one-shot) mounts /dev/vdb, executes command, writes result.json, powers off the VM 5. Host waits for VM process to exit 6. Host loop-mounts workspace, reads result.json, unmounts 7. Clean up Changes: - guest-runner.sh: converted from polling daemon to one-shot executor that halts the VM after writing results - microvm.ts execInMicroVm: complete rewrite for sequential model with createWorkspaceImage, mountExt4, unmountExt4 helpers - dag-orchestrator.ts executeMicroVm: simplified — no longer manages boot/destroy lifecycle, delegates to one-shot execInMicroVm All existing tests pass. Rootfs rebuilt and deployed to PVC.
Firecracker MicroVM Infrastructure
ADR-0230: Firecracker MicroVM Agent Sandboxes
Setup
Prerequisites
- Colima with
nestedVirtualization: true(requires VZ framework, Apple Silicon) /dev/kvmaccessible inside the Colima VM
Guest Images
Download from Firecracker CI (not committed to git):
BUILD="20260107-89702a77e4c2-0"
mkdir -p infra/firecracker/images
curl -sL "https://s3.amazonaws.com/spec.ccfc.min/firecracker-ci/${BUILD}/aarch64/vmlinux-6.1.155" \
-o infra/firecracker/images/vmlinux-6.1.155
curl -sL "https://s3.amazonaws.com/spec.ccfc.min/firecracker-ci/${BUILD}/aarch64/ubuntu-24.04.squashfs" \
-o infra/firecracker/images/ubuntu-24.04.squashfs
Firecracker Binary
FC_VERSION="v1.15.0"
curl -sL "https://github.com/firecracker-microvm/firecracker/releases/download/${FC_VERSION}/firecracker-${FC_VERSION}-aarch64.tgz" \
-o /tmp/firecracker-${FC_VERSION}-aarch64.tgz
tar xzf /tmp/firecracker-${FC_VERSION}-aarch64.tgz
# Install inside Colima VM:
colima ssh -- sudo cp release-${FC_VERSION}-aarch64/firecracker-${FC_VERSION}-aarch64 /usr/local/bin/firecracker
colima ssh -- sudo chmod +x /usr/local/bin/firecracker
Files
| File | Purpose |
|---|---|
stages.json |
10-step execution DAG for workload planner |
images/ |
Guest kernel + rootfs (gitignored, downloaded from CI) |
README.md |
This file |
Architecture
macOS (M4 Pro) → Colima VM (VZ, aarch64, nested virt) → /dev/kvm → Firecracker microVMs