SecondStack · Agent Platform

Where can Agents run code?

Every Agent runs its commands inside a sealed sandbox, never on the server itself. Two engines can build that sandbox. Which one you can use depends on one thing: does the server give access to CPU virtualization (KVM)?

Two sandbox engines

FIRECRACKER

A tiny real VM per Agent

The CPU hardware builds the wall. Each Agent gets its own Linux kernel.

Agent code
Its own Linux kernel
Hardware virtualization (KVM) the wall
Server
  • Needs /dev/kvm on the server
  • Isolation Strongest, enforced by hardware
  • Start Fast, can resume from snapshots
  • CPUs amd64 and arm64
  • Used by Docker Compose installs
GVISOR

A software kernel in between

A Linux kernel written as a normal program catches every request from Agent code.

Agent code
gVisor kernel, in software the wall
Small, filtered set of real calls
Server
  • Needs Nothing special, any Linux server
  • Isolation Strong, enforced by software
  • Start Cold start; heavy file I/O is slower
  • CPUs amd64 only
  • Used by Kubernetes install (PR #657)

Same for both: the same signed images, the same /workspace, the same network rules through our egress proxy. Agents cannot tell which engine they run on.

What kind of server do you have?

Bare metal

KVM ✓ native

A physical machine. Best speed and the most Agents per server.

FirecrackergVisor

VM, nested virtualization on

KVM ✓ with overhead

The hypervisor passes virtualization into the VM. Works, but it is a VM inside a VM. The cloud or hypervisor admin must enable it.

FirecrackergVisor

VM, no nested virtualization

KVM ✗

Most ordinary cloud VMs and managed Kubernetes nodes. Firecracker cannot start here.

FirecrackergVisor
Install typeBare metalVM + nested virtVM, no nested virt
Docker Compose Firecracker Firecrackerslower no local sandboxesRun the sandbox Runner on a separate KVM host
Kubernetes (#657) gVisor gVisor gVisorthe main target

Kubernetes: why gVisor

Kubernetes nodes are usually cloud VMs without KVM, and SecondBox supports only its gVisor Runner as a Kubernetes pod. So the Kubernetes install needs no virtualization at all.

  • One Linux host running K3s, amd64, Ubuntu 22.04/24.04
  • 4 CPU · 12 GiB · 64 GiB minimum, plus about 1 CPU and 1 GiB per active Agent sandbox
  • No KVM and no special CPU features
  • Multi-node clusters come later

Bottom line

“We have an ordinary cloud VM.”

Kubernetes install with gVisor. It runs anywhere.

“We run many Agents.”

Bare metal with Firecracker: the fastest and strongest option.

“We run our own hypervisor.”

Enable nested virtualization to get Firecracker; otherwise use gVisor.