Firecracker microVMs with SwarmKit orchestration

Docker Swarm UX with hardware-isolated VMs.

Gate 01 · one-line install
curl -fsSL https://raw.githubusercontent.com/restuhaqza/SwarmCracker/main/install.sh | sudo bash
WEB.1 · swk-8f2a sealed
WEB.2 · swk-3c71 sealed
WEB.3 · swk-b094 sealed
Illustrative example: three replicas of web, each a sealed Firecracker microVM on its own KVM boundary — placed and tracked by SwarmKit.

How it works

SwarmCracker slots a Firecracker microVM executor underneath SwarmKit. Tasks arrive as ordinary Swarm services; each replica is placed as its own sealed VM.

  1. Install SwarmCracker

    Run the one-line installer to download the binary, kernel image, and rootfs in a single step.

  2. Verify prerequisites

    Check that KVM is available, the host meets resource requirements, and required tools are installed.

  3. Set up networking

    Create the bridge and TAP device configuration that SwarmCracker uses to connect microVMs.

  4. Deploy a service

    Use the familiar docker service create syntax to launch your first container inside a Firecracker microVM.

Placement log swarmkit / executor
$ swarmcracker service create --name web --image nginx:alpine --replicas 3creating service "web" (3 replicas)...pulling image nginx:alpine ...extracting rootfs ...creating microVM for task web.1 ...booting kernel ...microVM web.1 started (1024 MiB, 2 vCPUs)creating microVM for task web.2 ...microVM web.2 started (1024 MiB, 2 vCPUs)creating microVM for task web.3 ...microVM web.3 started (1024 MiB, 2 vCPUs)service "web" converged (3/3 replicas)

Illustrative output — a sample service, not a live host.

SwarmCracker architecture: the SwarmKit manager sends tasks to the agent, which delegates to the SwarmCracker executor; the executor translates tasks, prepares images, sets up networking, and launches Firecracker microVMs via KVM.

Why SwarmCracker?

Six things the executor guarantees for every task it places — drawn from the same spec sheet the microVMs are built to.

SPEC 01 · KRNL

Per-VM kernel

Each microVM boots its own Linux kernel, so workloads are fully isolated at the hardware level rather than sharing a host kernel.

SPEC 02 · SWRM

SwarmKit compatible

Drop-in executor for SwarmKit. Use standard docker service commands to create, scale, and update services backed by Firecracker VMs.

SPEC 03 · KVM

KVM hardware isolation

Leverages KVM to provide hardware-enforced boundaries between workloads — stronger than namespace-based container isolation.

SPEC 04 · BOOT

~100 ms boot

Firecracker microVMs start in roughly 100 milliseconds, keeping service scaling responsive even under burst traffic.

SPEC 05 · NET

VXLAN cross-node networking

Built-in VXLAN overlay lets containers on different hosts communicate securely without external CNI plugins.

SPEC 06 · ROLL

Rolling updates

Standard SwarmKit rolling-update strategies work out of the box — update images, change resource limits, or roll back with familiar flags.

Quickstart

Seven loading orders take a bare Linux host to a running service. Copy each one in order — the whole run is a single bill of lading.

Load order host → yard
Install SwarmCracker
curl -fsSL https://raw.githubusercontent.com/restuhaqza/SwarmCracker/main/install.sh | sudo bash
Check prerequisites
sudo swarmcracker setup check
Download kernel & rootfs
sudo swarmcracker setup install --download-kernel --download-rootfs
Configure networking
sudo swarmcracker setup network
Write default config
sudo swarmcracker setup config --non-interactive
Initialize cluster
sudo swarmcracker cluster init --advertise-addr 192.168.1.10:4242
Create a service
swarmcracker service create --name web --image nginx:alpine --replicas 3

How it compares

Same Swarm-style workflow you already know, with a hardware boundary around every workload. Here is where that lands against Docker and Kubernetes.

SwarmCracker vs. Docker vs. Kubernetes
Aspect SwarmCracker Docker Kubernetes
Isolation KVM hardware virtualization per workload Shared kernel via namespaces and cgroups Shared kernel via namespaces and cgroups
Boot time ~100 ms (Firecracker microVM) ~50 ms (container start) ~50 ms (container start)
Orchestration SwarmKit (built-in) Docker Swarm / Compose Custom scheduler and control plane
Learning curve Familiar Docker Swarm commands Familiar Docker commands Steeper — YAML manifests, many abstractions
Networking Built-in VXLAN overlay Overlay / bridge networks Requires CNI plugin selection

Security

The boundary is the point. Every workload is sealed behind a KVM hardware edge, not a namespace in a shared kernel.

SEAL · KVM

Hardware-enforced boundaries

Each workload runs inside its own KVM virtual machine, so a kernel exploit in one VM cannot affect the host or neighbouring VMs.

  • Minimal attack surface

    Firecracker is purpose-built for serverless and microVM workloads — a small codebase with a reduced threat model compared to general-purpose hypervisors.

  • Jailer support

    SwarmCracker integrates Firecracker's jailer to further restrict each VMM process with cgroups, seccomp filters, and chroot jails.

  • Apache 2.0 licensed

    Fully open source under a permissive license. Audit the code, contribute fixes, and run it anywhere without vendor lock-in.