I'm having trouble understanding/believing this, given that Cloudflare Workers are also v8 isolates and run vastly faster than the 25-40ms that netlify says their isolates took...
from the article: "With our old infrastructure it went out over the internet, ran the edge function, and came back to us to pass on. With the new compute platform, the request is forwarded to a compute node within our network."
As far as I know, Cloudflare Workers have always executed within Cloudflare's network, not gone out to the internet and executed elsewhere (which I read as being in a hyperscaler cloud).
v8 isolates aren't actually a great sandbox and I would not trust them implicitly in the AI era. This is probably why they wrap them in an additional sandbox.
Alex from Unikraft here! Happy to answer any questions about the microVM part of the story from our side.
We also did a couple of write ups if you're interested:
- https://unikraft.com/blog/netlify-edge-functions
- https://unikraft.com/customer-stories/edge-functions-netlify
I'm having trouble understanding/believing this, given that Cloudflare Workers are also v8 isolates and run vastly faster than the 25-40ms that netlify says their isolates took...
> In the past, requests went out to a hosted execution service. Today, they run on MicroVMs inside our own edge network
The isolates were not being run at the edge.
They were running on the edge, and in the same datacenters but by another provider.
from the article: "With our old infrastructure it went out over the internet, ran the edge function, and came back to us to pass on. With the new compute platform, the request is forwarded to a compute node within our network."
As far as I know, Cloudflare Workers have always executed within Cloudflare's network, not gone out to the internet and executed elsewhere (which I read as being in a hyperscaler cloud).
Wish it explained where the v8 isolate latency is coming from compared to microvms
"In the past, requests went out to a hosted execution service."
They were outsourcing to another company so there's plenty of room for overhead to creep in.
v8 isolates aren't actually a great sandbox and I would not trust them implicitly in the AI era. This is probably why they wrap them in an additional sandbox.
Why are v8 isolates bad, I see speculative execution hacks, but are there others?
The v8 JIT is very complex and can lead to sandbox escapes if there are type confusion bugs.
Despite naming them isolates, the V8 team does not consider them to be a security boundary.
v8 isolates are still shared kernel
while microvm's are separate kernel + hardware virtualization through hypervisor guarantees
I wouldn't call it bad either, just different tools for different things
If you're counting milliseconds why use Javascript?
V8 is extremely optimized for script startup time.