{"repo":"herd-core/herd","free":true,"listed":false,"github":"https://github.com/herd-core/herd","clone":"git clone https://github.com/herd-core/herd.git","description":"microVM orchestrators to boot from docker images, packed with L7 reverse proxy","language":"Go","stars":38,"topics":["go","cloud","containerd-snapshotter","isolation","microvm","oci-image","orchestration","security"],"license":"Apache-2.0","category":"workflow-automation","readme_excerpt":"Herd: microvm hypervisor The initial goal was to create a lightweight, secure, and fast execution environment for running docker images. The problem with docker is that it has a major security issue with running containers on the same host. Any zero day exploit in the kernel through a container can lead to a full host compromise. Now, I am able to successfully run and deploy pre-pulled docker images as microvms. And they are lightning fast. I can start a microvm in under 500ms , and that includes all the networking, ingress, file system setup on demand. Different from firecracker Firecracker microvm is an amazing peice of technology but it's just a dumb hypervisor. It doesn't provide any host side setup for running OCI images, or networking, or ingress, or anything. You have to build all of that yourself. Herd provides all of that out of the box. The table below highlights the difference between firecracker and herd. Feature Raw Firecracker Herd :--- :--- :--- Input Custom Kernel + Raw ext4 Disk Image Standard Docker/OCI Image Storage Manually create disk images using dd OCI Translation : Automated image-to-snapshot. Network Creates a TAP device, you route the rest Automated IPAM : Host side NAT + routing. Ingress No ingress Wake-on-Request Proxy : Host port binding. Isolation Manually configure jailer for each microvm Automated Isolation : Herd auto configures jailer for each microvm. Lifecycle Turn On / Turn Off Scale to Zero : Cold-boots on first request [WIP]. User Experi","default_branch":null,"files":null,"tree":[],"storefront":"/r/herd-core","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/herd-core/herd/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}