
Firecracker einfach gemacht. Sichere MicroVMs in Millisekunden hochfahren – von der Installation bis zur interaktiven Shell mit einem Befehl.
🔥 Firecracker microVM Sandbox Toolkit
Erstellen, verwalten und verbinden Sie isolierte Firecracker‑microVMs von der Kommandozeile. Starten Sie eine sandboxierte VM in Millisekunden, führen Sie Befehle aus, übertragen Sie Dateien — kein SSH erforderlich.
--from-imagebase, node22, node24, python3.13--json‑Flag für Skripterstellung und Automatisierung--from-image)curl -fsSL https://vmsan.dev/install | bash
Dies lädt alles herunter und installiert es in ~/.vmsan/:
node22, node24, python3.13) als vorgefertigte Artefakte heruntergeladenStandard‑Releases laden integrierte Laufzeiten von https://artifacts.vmsan.dev/ herunter und benötigen kein Docker. Quellinstallationen bauen Laufzeiten weiterhin lokal.
curl -fsSL https://vmsan.dev/install | bash -s -- --uninstall
# Install dependencies
bun install
# Build the in-VM agent
cd agent && make install && cd ..
# Build the CLI
bun run build
# Link local build
mkdir -p ~/.vmsan/bin
ln -sf "$(pwd)/dist/bin/cli.mjs" ~/.vmsan/bin/vmsan
# Create and start a VM
vmsan create --runtime node22 --memory 512 --cpus 2
# Create a VM from a Docker image
vmsan create --from-image node:22-alpine
# List all VMs
vmsan list
# Execute a command inside a VM
vmsan exec <vm-id> ls -la
# Interactive exec with PTY
vmsan exec -i <vm-id> bash
# Connect to a running VM shell
vmsan connect <vm-id>
# Upload a file to a VM
vmsan upload <vm-id> ./local-file.txt /remote/path/file.txt
# Download a file from a VM
vmsan download <vm-id> /remote/path/file.txt ./local-file.txt
# Snapshot a running VM
vmsan snapshot create <vm-id>
# List snapshots
vmsan snapshot list
# Restore a VM from a snapshot
vmsan create --snapshot <snapshot-id>
# Stop a VM
vmsan stop <vm-id>
# Remove a VM
vmsan remove <vm-id>
| Flag | Beschreibung |
|---|---|
--json | Strukturierte JSON‑Ausgabe |
--verbose | Detaillierte Debug‑Ausgabe anzeigen |
| Befehl | Alias | Beschreibung |
|---|---|---|
create | Erstelle und starte eine neue microVM | |
list | ls | Liste alle VMs auf |
start | Starte eine gestoppte VM | |
stop | Stoppe eine laufende VM | |
remove | rm | Entferne eine VM |
exec | Führe einen Befehl in einer laufenden VM aus | |
connect | Öffne eine interaktive Shell zu einer VM | |
upload | Lade Dateien auf eine VM hoch | |
download | Lade Dateien von einer VM herunter | |
network | Aktualisiere die Netzwerkrichtlinie auf einer laufenden VM | |
snapshot | Verwalte VM‑Snapshots (erstellen, auflisten, löschen) | |
doctor | Überprüfe Systemvoraussetzungen und Installationsintegrität |
vmsan.toml (geplant für 0.5.0)nftables mit atomarer Regelanwendung für Netzwerkisolierung (seit 0.2.0)# Build
bun run build
# Link local build
ln -sf "$(pwd)/dist/bin/cli.mjs" ~/.vmsan/bin/vmsan
# Dev mode (watch)
bun run dev
# Run tests
bun run test
# Type check
bun run typecheck
# Lint & format
bun run lint
bun run fmt
bin/ CLI entry point
src/
commands/ CLI subcommands
services/ Firecracker client, agent client, VM service
lib/ Utilities (jailer, networking, shell, logging)
errors/ Typed error system
generated/ Firecracker API type definitions
agent/ Go agent that runs inside the VM
docs/ Documentation site (vmsan.dev)
/30‑Subnetz (198.19.{slot}.0/30)Der Zustand wird in ~/.vmsan/ gespeichert:
~/.vmsan/
vms/ VM state files (JSON)
jailer/ Chroot directories
bin/ Agent binary
kernels/ VM kernel images
rootfs/ Base root filesystems
registry/ Docker image rootfs cache
snapshots/ VM snapshots