finds.dev← search

// the find

smol-machines/smolvm

★ 6,394 · Rust · Apache-2.0 · updated Sep 2026

An embeddable, portable, branchable virtual machine to safely run Agents locally.

smolvm is a Rust runtime that boots hardware-isolated microVMs (via libkrun on KVM/Hypervisor.framework/WHP) to run untrusted or agent-generated code, with an emphasis on branching and checkpointing a running VM mid-execution. It's aimed at people building coding-agent sandboxes or agentic pipelines who need real kernel-level isolation instead of container namespaces, and who want SDK-level embedding rather than shelling out to a daemon.

Sub-200ms boot with per-workload VMs and elastic memory via virtio balloon is a real architectural win over QEMU/Kata-style setups, and it runs any OCI image with no Docker daemon required. Branching a live machine into copy-on-write children and checkpointing/rewinding execution state is genuinely different from Firecracker or gVisor — most sandboxing tools don't let you fork mid-run. The credential substitution model (inject a secret the guest process can use but never read) plus host-pattern egress allowlisting is a concrete security mechanism, not just marketing copy. Embeddable SDKs for Node/Python/Rust with no separate daemon process is a legitimate ergonomic advantage for integrating into an agent framework.

Windows support is second-class: no branching, no checkpoints, no GPU acceleration, which guts the two features that differentiate this from any other microVM tool if you're on that platform. The CUDA/GPU remoting stack (smolvm-cuda, cudart-shim, nvml-shim, driver stubs) is a large amount of low-level surface area reimplementing parts of the NVIDIA driver ABI — that's a lot of room for subtle correctness bugs and a maintenance burden that could easily lag real CUDA releases. macOS Intel is explicitly marked untested, so half of the Mac install matrix is unverified. The repo also vendors prebuilt binaries (dylibs, .so files for multiple arches) directly in git rather than fetching them at build or install time, which bloats every clone and makes provenance/supply-chain auditing harder.

View on GitHub → Homepage ↗

// want more like this?

We dig through GitHub every week and send a few repos picked for what you actually care about — each with an honest take like this one.

Get finds in your inbox → Search again →