← All experiments

Workshop · In release validation

fc-ctl: Isolated job execution

A self-hosted execution plane for asynchronous jobs in isolated Firecracker microVMs. It works without Kubernetes and enforces explicit limits for runtime, networking and resources.

Experiment status
In release validation
Area of inquiry
Bounded workloads in Firecracker microVMs
Outcome
Internal application

What are we trying to find out?

How can SaaS products execute third-party or automatically generated workloads without giving them access to the application host or other tenants?

01

Why does this matter to us?

Containers alone do not always provide the required security boundary. At the same time, full cluster platforms are often too complex for clearly bounded background jobs.

02

What did we build?

Controllers and workers form regional execution cells. Approved images are distributed immutably, jobs are transmitted with signatures and executed in short-lived microVMs with controlled networking, resource limits and reliable result delivery.

03

Where does the experiment stand?

The controller, workers, SDK, image pipeline, security hardening, recovery and operational metrics are implemented. Local release gates are complete; validation of the exact candidate on production-like Linux hardware is still pending.

04

What happens next?

Run host, S3 and recovery drills with the immutable release candidate and initially test the platform as the internal runtime for s3s.sh.

Technologies and topics

  • PHP 8.4
  • Firecracker
  • MicroVMs
  • Linux
  • S3
  • Security