Invest in NanoVMs!

Unikernel Tutorials

Virtio-RNG Inside Nanos

In the Nanos kernel, we have recently added support for the virtio-rng device. This virtio device allows applications to use it as a source of randomness without relying on dedicated processor instructions that may not be available in all clouds or hypervisors.

Sending memory metrics to Amazon CloudWatch

Thanks to a new kernel library, Nanos can now communicate with Amazon CloudWatch, the monitoring service for AWS applications and resources. This article explains how to set up a Nanos unikernel application so that its memory utilization metrics can be monitored via Amazon CloudWatch.

Closures in the Nanos Unikernel

This article does an overview on the use of closures in the Nanos kernel. Closures are common in languages like Ruby and Swift. The C language does not include them, thus, the Nanos kernel relies on its own implementation. We use closures not only to implement callbacks with saved variables but also to compose continuations for asynchronous operations. In this article, we present what a closure is and we show the dedicated API that the Nanos kernel provides to manipulate closures.

The Tuple Filesystem in the Nanos Unikernel

General Purpose Operating Systems use a filesystem (fs) to store data in a persistent way like on a hard disk. Generally speaking, data is stored in files which belong to a directory. Thus most filesystems are organized in a hierarchical way. The fs stores files in blocks into physical devices.

Running Nanos on AWS Graviton

With Nanos now able to run on AWS Graviton instances, we have the option of deploying a Nanos unikernel on public cloud VMs with processors other than Intel or AMD. This article shows how to run Nanos on a Graviton2 (64-bit ARM) instance, and explains some technical details involved in running an operating system on an ARM-based server platform.

Nanos on 64-bit RISC-V

Nanos can now be built for the riscv64 (64-bit RISC-V) architecture. We discuss how to cross-compile and run Nanos and RISC-V programs with QEMU, and also go over some of the technical aspects of porting Nanos to RISC-V.

Red-Black Trees in NanoVMs

Red-black trees (rbtrees) are data-structures widely used in the kernel. For example, this data-structure is one of the building blocks of the Linux scheduler. In this article, we overview general concepts about trees and then we focus on what makes rbtrees very interesting.

Bitmaps in NanoVMs

This article is an overview of bitmaps, which is a data-structure heavily used in the kernel. NanoVMs provides a dedicated API to handle bitmaps. In the following, we present the API to instantiate bitmaps and how this API is adapted to deal with different use-cases. Also, we present the kernel’s data-structures that are represented by using bitmaps.

Overview of EBPF in the era of Unikernels

This article overviews EBPF (Extended Berkeley Packet Filter), which is a recent technology available in the Linux kernel to add user-defined functionalities in the kernel. This article aims at understanding what EBPF is and its use-cases.

Running Unikernels on the Bhyve Hypervisor on FreeBSD

In this tutorial we show you have to run a Nanos unikernel on the Bhyve hypervisor on top of FreeBSD.

Creating a VPN Gateway with a Unikernel running WireGuard

The security advantages of unikernels make them a great fit for a public-facing dedicated network appliance such as a VPN gateway. With some special configuration, we can run a userspace WireGuard implementation on Nanos to make a gateway to a cloud private network.

Using NetConsole for Debug Logging of Unikernels

Nanos has many different logging options. You can log to serial, you can log to files, you can ship things over syslog. We even made a syslog klib so you don't have to modify your code. Today we'll show you yet another way to log.

Debugging Unikernels Using New Native TFS Tools

OPS recently gained native TFS dump support. TFS is the default filesystem for the Nanos unikernel. The new support allows you to run simple commands such as ls, cp, and tree directly on a Nanos image. You don't need FUSE and you can run this on a Mac too.

Profiling Unikernel Syscall Execution Time

It is no secret we like performance. Hell, we wrote our own kernel for that very reason. We've also made a lot of tooling in the past to help us find hotspots and make it easier to profile Nanos. Today we'll introduce you to another tool.

Autoscaling Unikernels with Instance Groups

Autoscaling has also been a common feature request from many users coming from a kubernetes environment. The cool thing about unikernels is that all of kubernetes complexity gets abstracted away since Nanos unikernels are deployed as virtual machines and the underlying cloud network and volume primitives are utilized versus duplicated with frameworks such as k8s.

CrossBuilding Unikernels on Mac without Docker or Vagrant

Some applications are hard to cross-compile on Mac if you are deploying to Linux servers. If you are using unikernels you might be relying on docker or vagrant to do this, however that is not necessary anymore with the new cross-compilation support for OPS.

Converting Docker Containers to Nanos Unikernels

Many Nanos/OPS users come from a docker background and there is a hidden implication that they might be working on a Mac for dev purposes. This can pose a problem for those that want to create their own software on a mac to run as a Nanos unikernel as Nanos consumes ELF binaries just like Linux does.

Nanos on 64-bit ARM Platforms

Nanos now targets platforms based on the aarch64 (64-bit ARM) architecture. In this tutorial, we'll learn how to build and run ARM unikernels, both on a Raspberry Pi 4 and as a cross-build from a non-ARM host. No ARM hardware required!

Embedding the Ruby and Python Interpreters into Nginx as a Unikernel

Ruby and Python are both popular interpreted languages. For many years developers that wished to deploy their Django, Rails and other applications written with these frameworks have routinely relied on front-end proxies such as Nginx and Haproxy and usually stuck those in front of a load balancer such as an ELB.

The Nanos Unikernel Now Has a FUSE Driver for TFS

One of our engineers just opened a PR for a FUSE driver for Nanos. What does this mean? It means you can now mount the filesystem natively on MacOS and Linux amongst other things.

Finding memory management errors in the Nanos Unikernel

Memory management errors are some of the most pernicious and most difficult bugs to troubleshoot. We can leverage the unique design of Nanos in order to create an small and efficient way of identifying these problems.

Running Mattermost as a Unikernel

Mattermost is an open source, private cloud slack alternative written in Go and React. It has many integrations and can can connect to mysql or postgres for persistence. While there are many "hello world" tutorials out there for running the Nanos unikernel we thought this would be a nice little example to showcase two things.

Understanding How to Use Klibs in the Nanos Unikernel

A while ago we wanted a pluggable method to instrument various stats in Nanos and we wanted to be able to apply this functionality to ad-hoc applications without having to re-write the code. So we took a page from the library operating system playbook and produced an inital draft for klibs in Nanos.

Working with Unikernel Volumes in Nanos

The most obvious time when you would want to attach a volume to your unikernel instance is when you are working with a database. Your database image probably doesn't change that much but many databases can grow very large and it makes no sense to keep the same data volume in your base image.

Debugging Nanos Unikernels with GDB and OPS

Some people think you can't debug unikernels. Tell that to the team of kernel engineers that routinely have to debug unikernels, sometimes without source code, sometimes without access to the system in question.

Profiling and Tracing the Nanos Unikernel

How does one go about profiling or tracing a unikernel? How do you login to the host and run perf or produce flame graphs? Isn't this impossible in a unikernel?

Autonomous Rust Unikernels in Google Cloud

Knowing the memory layout of an application and it's host operating system is vital to attacking a system. What if you could reboot an entire server in seconds and get a brand new memory layout each time? While not feasible with traditional linux vms and definitely not containers this is a uniquely cool unikernel feature.

Deploying Nanos Node.JS Unikernels to AWS

In this short tutorial we learn how to build, deploy, and run node.js unikenels to AWS using the t2 instance type.

Creation and Usage of Machine Learning Classification Models Using Unikernels

Learn to use machine learning classification with python3, sklearn and run them using unikernels.

InfluxDB Unikernels on Google Cloud

InfluxDB is a popular time series database that fits well inside an edge or IoT pipeline where you might be already using something like MQTT. If you're already using unikernels for your edge devices it might be a good idea to turn your time series datastore into one as well.

Unikernels from the Edge to the Cloud

MQTT is the quintessential protocol for edge and IoT devices to talk to the cloud for more than a few reasons. If you're a pumpjack in the middle of nowhere west texas 50 miles from town and you're in a field of said pumpjacks getting that data out can be a hassle.

Assessing Unikernel Security

A lot has been said about the security posture of unikernels. I know I've said a mouthful myself. ;) I originally wasn't going to write this article but I've now had to respond to the same question a number of times so my hand has been forced.

Running Forth Unikernels

Forth has been called lots of things and it was something that I figured we could easily unikernelize so I dove into it. I think it's safe to say I've never written any production Forth nor do I see myself doing so but having said that - let's begin!

Running WASM Unikernels

WASM is a new way of transpiling high level languages to a common binary format. Here we show how we can take WASM and run it as a unikernel.

Logging Go Unikernels to PaperTrail

Learn how to implement logging in your Go unikernels with a Free Account from PaperTrail.

Running Go Unikernels

After running my first c example in rumprun a few years ago the next language I wanted to try out was Go. Unfortunately there were no Go unikernels at the time so we sponsored one for rumprun. That was 3 years ago.

Running Node.JS Unikernels

Javascript developers were some of the earliest adopters of things like containers, serverless and other infrastructure patterns so it's not surprising that unikernels interest them too.