I wanted to see how fast an isolated code sandbox could start if I never had to boot a fresh VM.So instead of launching a new microVM per execution, I boot Firecracker once with Python and numpy already loaded, then snapshot the full VM state. Every execution after that creates a new KVM VM backed by a `MAP_PRIVATE` mapping of the snapshot memory, so Linux gives me copy-on-write pages automatically.That means each sandbox starts from an already-running Python process inside a real VM, runs the code, and exits.These are real KVM VMs, not containers: separate guest kernel, separate guest memory, separate page tables. When a VM writes to memory, it gets a private copy of that page.The hard part was not CoW itself. The hard part was resuming the snapshotted VM correctly.Rust, Apache 2.0.
FL score
out of 100
Verdict
high confidence
Competition
10
competitors found, nascent market, big tech present, funded players
Trend
5 community mentions
A platform offering sub-millisecond KVM sandboxes for AI agents, leveraging CoW memory forking to solve latency and cost at scale.
The pain
The gap
Build angle
Strengths
Questions about this idea?
FlyBot reads the scoring and gives you a second opinion on “Sub-millisecond VM sandboxes using CoW memory forking”.
Risks
Next steps
Fly Labs Method
Is the pain real, is there a gap, is it the right time, can one person build it.
A highly technical idea with clear demand from AI agent developers for ultra-low latency sandboxes, but faces strong competition and significant build complexity for a solo founder.
Value Equation
Dream outcome and how likely it feels, against the time and effort it costs.
The idea targets a growing, high-value problem in the AI space but requires significant technical execution and faces established competition.
One-Person Business
Curiosity pull, identity fit, and a path from free value to paid for a solo creator.
A technically challenging but clearly needed solution for a specific developer audience, assuming the builder has deep expertise.
Viral Frameworks
Hook strength, shareability, and how cheaply it can be tested.
Strong value prop for a clear audience, but faces high technical and market validation risks for a micro-SaaS.
Builder Lens
Evidence the problem exists, timing, defensibility, and a model that fits on a napkin.
Addresses a critical, growing need for ultra-fast, secure compute in AI, with a clear narrow entry point, but needs strong execution.
Why this verdict
Five lenses, one composite. How scoring works
The angle
This weekend
Who is already there, nascent market
Sub-millisecond (0.8ms p50) VM sandboxes via CoW memory forking of Firecracker snapshots into KVM VMs for isolated code execution, preloaded with Python/Numpy.
Pricing: free (open source)
API for instant microVM sandboxes to run AI-generated code securely, supports git sources, commands, ports, runtimes like Node.
Pricing: active CPU pricing (pay per use)
Instant Linux microVMs with TypeScript/Python SDKs + REST API, secure against prompt injection for code execution.
Pricing: unknown (likely pay per use)
Self-hosted platform for running untrusted/AI-generated code with microVM speed + container UX, full hardware isolation.
Pricing: free (open source)
Persistent sandboxes (<60ms spin-up) for AI agents, isolated minicomputers for multi-step workflows, state saving, API control.
Pricing: pay per use ($500 spend commitment for full internet)
Serverless platform with ridiculously fast sandboxes/containers for AI/ML, supports forking VMs, cheap for many parallel runs.
Pricing: pay per use (e.g. $0.10 for 30 sandboxes)
Secure cloud sandboxes/infrastructure for AI code interpreters/agents, fast spin-up, millions/month, supports code/terminal/packages/files.
Pricing: pay per use (free credits for startups)
Offers cloud development environments with fast VM cloning (within 2 seconds) by using Copy-on-Write for filesystem and then userfaultfd for in-memory CoW. This allows forking of running VMs for immediate development environment duplication.
Pricing: Not explicitly detailed for CoW forking, but offers various plans for development environments.
An open-source project that runs container workloads inside lightweight VMs, providing stronger workload isolation using hardware virtualization. Each container gets its own kernel and memory space, with minimal overhead (around 20-30 MB per VM) and sub-second boot times. It supports various hypervisors including Firecracker and uses CoW for security concerns in containers.
Pricing: Open-source, no direct pricing.
Google's sandboxing technology for containers, reimplementing the Linux kernel in userspace to intercept syscalls. It aims to provide strong isolation. While it uses memory management, explicit CoW memory forking for sub-millisecond VM sandboxes as described in the problem is not its primary feature, and it has shown issues with drastic memory increases when multiprocessing with Python due to CoW interactions.
Pricing: Open-source, no direct pricing.
Gaps they leave open
What people say, 5 mentions
eLearning platform
r/Entrepreneur
I wanted an Airbyte alternative that doesn't eat RAM, so I built one in Rust (SQL-based)
r/SaaS
2026 AI Coding Agent Dev Tool Market Map
r/SaaS
A dev tool isn’t a dev tool until it has a 4-panel editor (even if my design is "Engineer-forward")
r/SaaS
Save Hours Debugging with This 10-Second Commenting Habit, What’s Your Worst Bug Story?
r/SaaS
Recent news
Show HN: Sub-millisecond VM sandboxes using CoW memory forking
Hacker News, March 18 2026
Show HN: Zeroboot – sub-millisecond VM sandboxes using CoW memory forking
Hacker News, March 17 2026
ZeroBoot: Sub‑millisecond VM Sandbox with Copy‑on‑Write Forking
UBOS.tech, March 18 2026
[New Project Friday] ZeroBoot – sub-millisecond VM sandboxes using Firecracker + KVM copy-on-write forking (self-hostable)
Reddit (r/selfhosted), March 20 2026
Sub-millisecond VM sandboxes for AI agents via copy-on-write forking
daily.dev, March 18 2026
Market signals
There is a strong and recent surge of interest in sub-millisecond VM sandboxing using CoW memory forking, particularly driven by the demand for fast and secure execution environments for AI agents and serverless functions, with new open-source projects and related discussions appearing on platforms like Hacker News and Reddit. Existing solutions like CodeSandbox, Daytona, E2B, and Modal address similar needs but may not achieve the same sub-millisecond VM fork times, indicating a potential market gap for ultra-low-latency cold starts.
Last summer we faced a conundrum at my company, Tiger Data, a Postgres cloud vendor whose main business is in timeseries data. We were trying to grow our business towards emerging AI-centric workloads and wanted to provide a state-of-the-art hybrid search stack in Postgres. We'd already built pgvectorscale in house with the goal of scaling semantic search beyond pgvector's main memory limitations. We just needed a scalable ranked keyword search solution too.The problem: core Postgres doesn't provide this; the leading Postgres BM25 extension, ParadeDB, is guarded behind AGPL; developing our own extension appeared daunting. We'd need a small team of sharp engineers and 6-12 months, I figured. And we'd probably still fall short of the performance of a mature system like Parade/Tantivy.Or would we? I'd be experimenting long enough with AI-boosted development at that point to realize that with the latest tools (Claude Code + Opus) and an experienced hand (I've been working in database systems internals for 25 years now), the old time estimates pretty much go out the window.I told our CTO I thought I could solo the project in one quarter. This raised some eyebrows.It did take a little more time than that (two quarters), and we got some real help from the community (amazing!) after open-sourcing the pre-release. But I'm thrilled/exhausted today to share that pg_textsearch v1.0 is freely available via open source (Postgres license), on Tiger Data cloud, and hopefully soon, a hyperscalar near you:https://github.com/timescale/pg_textsearchIn the blog post accompanying the release, I overview the architecture and present benchmark results using MS-MARCO. To my surprise, we were not only able to meet Parade/Tantivy's query performance, but exceed it substantially, measuring a 4.7x advantage on query throughput at scale:https://www.tigerdata.com/blog/pg-textsearch-bm25-fu
AI
Hi HN!I recently switched from a Fedora/GNOME laptop to a MacBook Air. My old setup served me well as a portable workstation, but I’ve started traveling more while working remotely and needed something with similar performance but better battery life. The main thing I missed was a simple taskbar that shows the windows in the current workspace instead of a Dock that mixes everything together.I built boringBar so I would not have to use the Dock. It shows only the windows in the current Space, lets you switch Spaces by scrolling on the bar, and adds a desktop switcher so you can jump directly to any Space. You can also hide the system Dock, pin apps, preview windows with thumbnails, and launch apps from a searchable menu (I keep Spotlight disabled because for some reason it uses a lot of system resources on my machine).I’ve been dogfooding it for a few months now, and it finally felt polished enough to share.It’s for people who like macOS but want window management to feel a bit more like GNOME, Windows, or a traditional taskbar. It’s also for people like me who wanted an easier transition to macOS, especially now that Windows feels increasingly user-hostile.I’d love feedback on the UX, bugs, and whether this solves the same Dock/Spaces pain for anyone else.P.S. It might also appeal to people who feel nostalgic for the GNOME 2 desktop of yore. I started my Linux journey with it, and boringBar brings back some of that feeling for me.
AI
### Describe the project you are working on Godot C# bindings ### Describe the problem or limitation you are having in your project For the past weeks, I've been discussing with several Unity users intending to move to Godot C# regarding dealing with the C# garbage collector. The most common complaint I hear from users is that, in Unity, allocations can trigger unexpected GC spikes into the game. In Godot, we target to make all of the high performance APIs (those that intended to be called every frame) not allocate any memory, so theoretically the GC should not be a problem. Additionally, Godot starting from 4.0, uses the Microsoft CoreCLR version of .net, which also supposedly has a better garbage collector than Unity. But in all, after several discussions with Unity users, neither is enough reassurance for them, and they would really feel safer if Godot exposed a zero allocation API. ### Describe the feature / enhancement and how it helps to overcome the problem or limitation The idea of this proposal is that Godot exposes zero allocation versions of many functions in the C# API, that users can use if they desire. Technically, this could be done from the binding generator itself, without breaking compatibility, and without doing any modification to Godot itself. ### Describe how your proposal will work, with code, pseudo-code, mock-ups, and/or diagrams **WARNING** I am not familiar with C#, so take this as pseudocode. Imagine you have two functions exposed as to C#: ```C# void MyClass.SetArray( Vector2[] array); Vector2[] MyClass.GetArray(); ``` This works and is pretty and intuitive. However, it has two problems: * GC is allocated on return * Memory is copied to Godot native formats every time there is a call. The idea is to add NoAlloc versions, which can be generated directly by the binder automatically when required: ```C# void MyClass.SetArrayNoAlloc( Godot.Collections.PackedVector2Array array); void MyCl
AI