Skip to content

MicroVMs overview

A MicroVM is a lightweight virtual machine, built on the open-source Firecracker hypervisor, that starts in about a second and runs a single container-style workload: a code sandbox, a small web app, or a CI job runner. MicroVMs are billed by the second or by the minute rather than by the month, and most of them are meant to be short-lived.

In the user panel, MicroVMs live under their own MicroVM section: MicroVM > Images, MicroVM > MicroVMs, MicroVM > Connectors and MicroVM > API keys.

  • Image: a template that describes what runs inside the MicroVM. You build one from a Dockerfile, a container image reference, or a Git repository. See Create an image.
  • Image version: every build of an image produces a new version. The current version is what new MicroVMs use by default.
  • MicroVM: a running (or paused, or stopped) instance of an image version, with its own plan, network and lifecycle settings. See Create a MicroVM.
  • Connector: an integration that launches MicroVMs automatically as CI runners in response to GitHub Actions or GitLab CI jobs, instead of you creating them by hand. See Connectors.

Every MicroVM has three independent settings that control its lifetime:

  • Maximum lifetime: a hard cap on how long the MicroVM runs, from the moment it is created. Leave it empty for no cap beyond the platform default. When it elapses, the MicroVM is either paused or killed, depending on When the lifetime ends.
  • When the lifetime ends: Pause keeps the MicroVM’s state on disk so it can be resumed later, or Kill destroys it outright. This choice only matters if a maximum lifetime is set.
  • Idle pause: pauses a MicroVM automatically after it has been idle for this long, independent of the maximum lifetime. Leave it empty to never idle-pause. This is skipped entirely while Always on is enabled.

Always on exempts a MicroVM from idle-pause and keeps it in continuous use; a platform housekeeping job restarts it automatically if it ever lands in an error state. A maximum lifetime, if set, still applies to an always-on MicroVM.

Every MicroVM has a public network, a VPC network, or both - there is no way to create one with no network at all. A public network gets an automatically assigned public IPv4 (or one of your own static IPs); a VPC network gets a private address from one of your VPC subnets, with outbound internet through that VPC’s NAT gateway. See Networking for the full model. On top of that, HTTP ingress can expose one port (plus extra ports) to the internet at an automatically-generated hostname or a custom domain, and shell ingress opens an interactive web terminal. Shell ingress needs an image built from, or based on, the platform’s sandbox-base image; see Web shell, logs and metrics.