trailofbits / trailofbits/coop

Firecracker hardening

Open
#5 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
Rust
Stars
243
Forks
13
Avg merge
1d 20h
Merged PRs (30d)
30

Description

Currently Firecracker VMs run without the jailer. For production and multi-tenant deployments, additional hardening should be applied:

  • Jailer integration: Run Firecracker inside its jailer for filesystem and device isolation
  • Seccomp filters: Restrict syscalls available to the VMM process
  • Per-tap networking: Each instance gets its own TAP device with no shared bridge, providing L2 isolation between instances
  • Resource limits: cgroup-based CPU and memory limits on the VMM process, with monitoring to surface resource exhaustion

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

The issue names no files, tests, or entry points; first locate the Firecracker VM launch path and the code responsible for TAP networking and process limits. Read how the project currently starts VMs, then scope the jailer, seccomp, per-instance TAP, and cgroup requirements; done means all four hardening areas are implemented and resource exhaustion is surfaced.

Written by the indexing model from the issue text.

Assessment

Tech stack
rust
Domain
infrastructure, networking, security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Quiet
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.