1. V8 isolates offer weak security isolation
- londons_explore: "They're shared process, shared address space, shared memory pool and allocator… In fact, there is very little isolated about them at all."
- vmg12: "v8 isolates aren't actually a great sandbox and I would not trust them implicitly in the AI era."
- phickey: "Despite naming them isolates, the V8 team does not consider them to be a security boundary."
2. Performance and latency motivated the shift to microVMs
- nchmy: "I'm having trouble understanding/believing this, given that Cloudflare Workers are also v8 isolates and run vastly faster than the 25‑40 ms that Netlify says their isolates took…"
- wmf: "In the past, requests went out to a hosted execution service."
- irq-1: "> In the past, requests went out to a hosted execution service. Today, they run on MicroVMs inside our own edge network"
- phickey: "With our old infrastructure it went out over the internet, ran the edge function, and came back to us to pass on. With the new compute platform, the request is forwarded to a compute node within our network."
3. Trade‑offs and suitability for different workloads
- torginus: "But I guess they are good enough to isolate multiple instances of the same code, ran by the same customer in parallel."
- Normal_gaussian: "Without commenting on v8 isolates specifically, this doesn't necessarily hold in any isolation situation; many customers are running code on behalf of their customers…"
- jst1fthsdys: "25 USD/m to run a daemon on my own hardware. Yikes."
- CodesInChaos: "…forked RNG states can lead to catastrophic failures in UUID generators or cryptography."
- ameliaquining: "Firecracker has existing solutions to this…"