惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

P
Privacy & Cybersecurity Law Blog
酷 壳 – CoolShell
酷 壳 – CoolShell
宝玉的分享
宝玉的分享
V
V2EX
爱范儿
爱范儿
Last Week in AI
Last Week in AI
美团技术团队
人人都是产品经理
人人都是产品经理
WordPress大学
WordPress大学
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
博客园 - 叶小钗
cs.CV updates on arXiv.org
cs.CV updates on arXiv.org
Apple Machine Learning Research
Apple Machine Learning Research
Security Latest
Security Latest
C
Cybersecurity and Infrastructure Security Agency CISA
Know Your Adversary
Know Your Adversary
I
Intezer
K
Kaspersky official blog
阮一峰的网络日志
阮一峰的网络日志
大猫的无限游戏
大猫的无限游戏
T
Tenable Blog
AWS News Blog
AWS News Blog
小众软件
小众软件
博客园 - 司徒正美
Cyberwarzone
Cyberwarzone
NISL@THU
NISL@THU
博客园 - 三生石上(FineUI控件)
C
CERT Recently Published Vulnerability Notes
博客园 - 聂微东
量子位
有赞技术团队
有赞技术团队
S
Schneier on Security
cs.CL updates on arXiv.org
cs.CL updates on arXiv.org
S
Secure Thoughts
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
罗磊的独立博客
Hugging Face - Blog
Hugging Face - Blog
V
Visual Studio Blog
Google DeepMind News
Google DeepMind News
L
Lohrmann on Cybersecurity
P
Palo Alto Networks Blog
P
Privacy International News Feed
L
LINUX DO - 最新话题
博客园 - Franky
雷峰网
雷峰网
月光博客
月光博客
Hacker News: Ask HN
Hacker News: Ask HN
Forbes - Security
Forbes - Security
博客园 - 【当耐特】
C
Cyber Attacks, Cyber Crime and Cyber Security

Hacker News

analog.watch I Replaced Whisper with Parakeet on a $55/Month CPU Server. Here Is What Actually Happened. HyperSwitcher – Mac App & Window Switcher CLERC-DATA/epee · Datasets at Hugging Face GitHub - gladiaio/gladia-cli EvenKeel — your money coach Build a Second Brain That Actually Remembers Why It Changed Tokenstead - Find AI Models for Your Hardware Fideby - Standing by the people you trust, when you can rubber duck GitHub - forgedculture/legibility-field-kit GitHub - ronak-create/FableCut: Zero-dependency browser video editor that AI agents can drive — JSON timeline, MCP + REST, live-reloading UI GitHub - BuceaGeorgia/VIRENA: A minimal Vision-Language-Action model you can read: frozen CLIP + a tiny head on ManiSkill PickCube. Runs on a Mac, no GPU. Fehu - Apps on Google Play GitHub - fresswolf/Slopera: The browser for the slop era Release Kiyeovo 1.0.0 · Realman78/Kiyeovo Noema — AI Company Analysis GitHub - hamidi-dev/opentab: 📊 Browse your AI coding spend in the terminal — OpenCode, Claude Code, Codex & more GitHub - sgInnora/wc2026-prediction-ledger: Receipt-verified AI prediction ledger for World Cup 2026: pre-kickoff sha256-locked forecasts scored vs results, with calibration + market baselines. Live: goalpulse.io/open-data GitHub - michaelwrites67-ctrl/yogen: 予言 Yogen — a 500-agent AI swarm that debates your idea and predicts the outcome. Self-host free with your own Anthropic key. GitHub - teddytennant/wizard: Self-extending autonomous agent in one Rust binary. One-line install, any provider (OpenAI-compatible, Anthropic, xAI) or fully local via llama.cpp, live /evolve self-modification, MCP, messaging gateway, built-in bench arcaide.foo Show HN: Android Developer Verification Package blacklisted in Aurora Store OpenDescent: Private messaging for normal people GitHub - tarunlnmiit/autopilot-jobhunt: AI job agent: scans 130+ careers pages nightly, scores every role against your resume with an LLM (0–100), alerts you on Telegram, and drafts tailored cover letters + resumes. Free & open source. 18 Words - Daily Word Challenge The State of US Local Government Accessibility 2026 flow - Real-time network throughput dashboard for the terminal. - Terminal Trove Battle LLM Robots GitHub - robesris/ffvii-realtime: Speed up Final Fantasy VII (Rebirth / Remake / Revelation) Tactical Mode slow-motion so combat plays at real-time speed Agent Sessions - Local History for AI Coding Agents Scrutora — code, cloud & consent compliance in one platform SoulOS Tutorials GitHub - gaemi/agentic-fc: Open-source football management simulation played by AI agents through MCP and watched through a TUI console. GitHub - talalalrwas/ocr-grab: Flameshot clone that adds OCR. GitHub - saifmukhtar/kinetic figment computer linear.gratis - Free Linear Client Feedback Forms GitHub - atelier-ws/atelier: Runtime for coding agents. Models are getting smarter, but a model is only as capable as the environment supporting it. Atelier is that environment. https://atelier.ws Atlas · Tomesphere | Tomesphere Codenames Generator GitHub - lyfeninja/lyfeninja_blkseal_python_sdk: Lightweight Python client for signing and verifying digital content using lyfe.ninja's BlkSeal product powered by BlkBolt™. Designed for zero dependencies, simple integration, and exact content verification. DateTimeMate OpenScreenShot — Full-page screenshot & annotation tool for Chrome 38-0 — Build Your Premier League Dream Team Cyrinx — data over sound, measured GitHub - BhaveshThapar/mcp-audit Probed — Talk to Your People HN Work GitHub - Northwood-Systems/foreman: Self-hosted LLM gateway. Cost effective, deterministic, and fast. Secure and private by default. A Visualization Language for the AI Era GitHub - weirdGuy/kastor: Declarative language and toolchain for AI agents: define agents, tools and prompts in HCL, then compile to frameworks or manage them on hosted platforms with plan/apply semantics. Abralo - Run multiple Claude Code agents in one window GitHub - mehranzand/repofleet: RepoFleet is an issue-centered CLI tool for managing Git workflows across multiple repositories. Pug — Open Source Product Analytics Chiptune Radio — Aleph Void, LLC Free Mermaid Live Editor & Diagram Maker GitHub - hirasso/html-obfuscator: Obfuscate emails, phone numbers, and other sensitive data in PHP. Invisible to humans, hidden from bots until they interact. Davit — a native macOS UI for Apple containers Fenzo AI - The perfect course, every time. HTML Drive — Edit and Publish HTML from Google Drive GitHub - rowboatlabs/rowboat: Open-source AI coworker, with memory ZeroGate | Automated Cluster Scaling A tiny scale-free kernel language — Joa Ebert GitHub - arman-jalili/guardian-framework: Architecture Enforcement Framework for AI-Assisted Development Yamanote.fun PostgreSQL on AWS: Size & Benchmark EC2 Instances GitHub - Rodiun/frugon: Free, local, open-source LLM cost analyzer — see where your LLM bill leaks, on your machine. Artificiety — A Fantasy World for AI Agents Ex Situ FlexInference: Drop your AI costs today WhimFiles - Find Any File in Seconds GitHub - josephsenior/Grinta-Coding-Agent: Local-first autonomous coding agent that plans, executes, validates, and finishes software tasks end-to-end. Nectar — The Web Without JavaScript Agent Draw: An agent draws while you talk, built on TLDraw Captchainbox - Make senders work to get into your inbox GitBiased — your whole engineering org, on one calm dashboard Neil the Seal GitHub - animesh-94/Onboard-CLI: An AST-powered, local-first CLI that visualizes complex system architectures and enforces architectural boundaries via instant Git hooks. ridealong — live London trains GitHub - rubix-studios-pty-ltd/rubix-redis-bridge: Secure production-hardened Rust HTTP bridge for Redis with Upstash-style API compatibility, command allowlisting, hard-denied dangerous Redis commands, Docker deployment, and SDK compatibility tests. Chauffeur – Deine Arbeitsumgebung mit einem Klick zurück Clusy | Agent-Native Notebook for ML and Data Science GitHub - dogtorjonah/context-warp-drive See what your community is paying attention to. GitHub - puffinsoft/peek-cli: Let coding agents see your browser. GitHub - vicmaster/framesmith: Open-source MCP server that gives AI assistants a visual design canvas, rendering HTML/CSS scene graphs to PNG via headless Chromium. snowscroll · Instagram, without the spiral. The Tree of "Tree" GitHub - Arthur-Ficial/translate: On-device translator for macOS Tahoe — UNIX filter + drop-in HTTP server compatible with DeepL, LibreTranslate, and Google v2. 100% on-device, no cloud, no LLM, no API keys. GitHub - agenthatch/agenthatch: Where agents hatch. GitHub - loopgain-ai/loopgain: An open-source cost controller for AI agent loops — stops a loop when it's actually converged and rolls back before it degrades, instead of running to a fixed max_iterations cap. Real-time loop-gain (Aβ) bands + best-so-far rollback. Adapters for LangGraph, CrewAI, AutoGen, LangChain, OpenAI Agents, and Claude Agent SDK; raw API for custom stacks. GitHub - vishal-dehurdle/state-harness: Runtime safety net for LLM agents. Detects token spirals, kills doomed tasks early, tells you exactly why. Rust core, Python SDK. pip install state-harness GitHub - the0cp/pico: A small, compact, register-based scripting language and virtual machine implemented in C. Inspired by clox. GitHub - nodes-app/swift-markdown-engine: A native AppKit Markdown editor for macOS, built on TextKit 2 and bridged to SwiftUI. GitHub - DO-SAY-GO/freelang: I love freelang GitHub - samchon/ttsc: A `typescript-go` toolchain for compiler-powered plugins and type-safe execution + 500x faster lint integrated into compiler GitHub - michaelaz774/decision-engine: A decision operating system for startup founders, powered by Claude Code. Synthesizes wisdom from 25+ legendary founders and investors into interactive AI-driven decision frameworks. GitHub - Chrilleweb/dotenv-diff: Validate environment variable usage in your codebase GitHub - skorotkiewicz/rudo: A small, elegant dock for Wayland
GitHub - instavm/tarit: A hypervisor and sandbox cloud for self-hosted AI agents and RL
mkagenius · 2026-07-08 · via Hacker News

The fastest hypervisor and sandbox cloud for AI agents and RL environments.

Tarit is a microVM platform for secure, fast, ephemeral sandboxes, built for AI agent workloads. It boots a real hardware-virtualized VM in milliseconds, runs a task inside it, and tears it down, giving each sandbox kernel-level isolation instead of a shared-kernel container boundary.

It has two parts, developed together in this monorepo:

  • vmm/ - the Tarit VMM, a minimal rust-vmm based microVM monitor (the hypervisor layer). One process runs one microVM. Usable on its own or under any orchestrator.
  • orch/ - taritd, a multi-node orchestrator and PaaS control plane that launches and manages microVMs across a fleet, with placement, warm pools, networking, snapshots, SSH/PTY access, per-key usage stats, and an audit trail.

They talk over a Unix-domain-socket protocol whose types live in one shared, dependency-light crate, proto/ (tarit-proto). That crate is the wire contract, so you can drive the VMM from taritd or from your own control plane without hand-copying types.

Why microVMs

  • Real isolation. Each sandbox is a KVM guest with its own kernel, not a namespaced process. A compromised or runaway workload cannot see the host or its neighbors.
  • Fast and cheap. Minimal device model (MMIO virtio only, no PCI, no BIOS), demand-paged guest RAM, and snapshot/restore for sub-second starts.
  • Ephemeral by design. Create, run, discard. Snapshots and copy-on-write overlays make many identical sandboxes cheap to spin up.
  • Built for agents. vsock-based exec and interactive PTY, per-key usage metering and audit, and an orchestrator tuned for bursty create/exec/destroy.

The VMM vs Firecracker

Tarit column from bare-metal validation; Firecracker column from its published docs.

Tarit, bare metal (p50) Firecracker
Ready to exec from snapshot 83 ms (node -v result) no published number
Snapshot restore to running VM 2.9 ms no published number
Warm-pool VM handout 12.3 ms n/a
Exec round trip in a running VM 0.6 ms n/a, no exec agent
Full snapshot, 256 MiB 60 ms, guest keeps running pause required
Live snapshot of a running guest yes no
Suspend that releases guest RAM yes no
PTY over the API yes serial console only
OCI image boot built in no
Egress filtering per-VM allowlist + rate limits rate limits only

Architecture at a glance

            HTTP API + CLI + SSH gateway
                        |
                   taritd (orch)          one multi-node control plane
                   /      |     \          placement, warm pool, fleet
                  /       |      \         usage + audit -> PostgreSQL
        vmm serve   vmm serve   vmm serve  one process per microVM
           |            |           |
        microVM      microVM     microVM   KVM guest, own kernel

taritd and any third-party orchestrator speak the same tarit-proto protocol to vmm serve: one length-prefixed JSON request, one response, over a per-VM Unix socket. See vmm/docs/INTEGRATION.md for bring-your-own-orchestrator.

Quickstart

The quickstart is layered. Layer 1 gets your code running in a microVM. Layer 2 adds snapshots, suspend, and restore. Layer 3 runs a managed fleet with the orchestrator. Take only the layer you need.

You need a Linux host with KVM (/dev/kvm) and a Rust toolchain. Running microVMs needs root (or membership in the kvm group), so the commands use sudo.

Layer 1: run code in a microVM

git clone https://github.com/instavm/tarit && cd tarit
sudo make install      # build + install vmm, taritd, and the guest agent
sudo make guest        # one-time: build a guest kernel + pull an Ubuntu rootfs

make guest does the slow work once (kernel build + OCI pull) and writes guest-assets/vmlinux and guest-assets/rootfs.ext4, so starting a VM afterwards is instant. Boot one, run a command in it, tear it down:

sudo vmm serve --socket /tmp/vm.sock &
sudo vmm --socket /tmp/vm.sock create --kernel guest-assets/vmlinux --rootfs guest-assets/rootfs.ext4
sleep 12                                             # let the guest boot and dial the agent
sudo vmm --socket /tmp/vm.sock exec "uname -a"
sudo vmm --socket /tmp/vm.sock stop

Only want the hypervisor? sudo make install-vmm installs just vmm.

Layer 2: snapshot, suspend, restore

Drive the same socket to capture and move VM state. A full snapshot writes memory plus device state; --diff writes only dirty pages. Suspend releases resident guest RAM; resume brings it back. Restore boots a fresh VMM from a snapshot.

sudo vmm --socket /tmp/vm.sock snapshot              # full snapshot, prints the .snap path
sudo vmm --socket /tmp/vm.sock snapshot --diff       # incremental (dirty pages only)
sudo vmm --socket /tmp/vm.sock suspend               # release resident guest RAM
sudo vmm --socket /tmp/vm.sock resume
sudo vmm restore --snapshot /path/to.snap            # restore into a new VMM process

Tarit also does live snapshots: a memory-consistent snapshot of a running guest with no downtime, so a busy VM can be checkpointed or forked. See vmm/docs/STANDALONE.md for the full device, egress, jailer, and PTY surface.

Layer 3: run a fleet with the orchestrator

taritd manages many microVMs across one or more nodes over an HTTP API, with placement, warm pools, per-key usage accounting, and an SSH/PTY gateway. Single node:

cd orch
TARIT_API_KEY=$(openssl rand -hex 24) \
TARIT_VMM_BIN=$(command -v vmm) \
TARIT_KERNEL=$PWD/../guest-assets/vmlinux TARIT_ROOTFS=$PWD/../guest-assets/rootfs.ext4 \
  taritd serve

Then create and drive VMs over HTTP, and scale to a multi-node cluster:

Repository layout

vmm/     the Tarit VMM (microVM monitor) - its own cargo workspace
orch/    taritd, the orchestrator and PaaS control plane - its own cargo workspace
proto/   tarit-proto, the shared UDS wire protocol crate (KVM-free)

vmm/ and orch/ are independent cargo workspaces so the VMM can be built, tested, and consumed on its own. Both depend on proto/ for the wire types.

Documentation

Platform support

  • Host: x86_64 Linux with KVM. Development also works on macOS for building and cross-checking; running microVMs needs KVM.
  • Not yet implemented: aarch64 guests, virtio-balloon.

Self-hosting

Self-hosting has been tested on AWS and GCP. Azure support is coming soon.

License

Tarit is licensed under AGPL-3.0-or-later. See LICENSE.