diff --git a/astro.config.mjs b/astro.config.mjs index a5e71ba..4c8d377 100644 --- a/astro.config.mjs +++ b/astro.config.mjs @@ -5,10 +5,27 @@ import starlightBlog from 'starlight-blog'; export default defineConfig({ site: 'https://hyperlight.org', + // Sites of other hyperlight-dev projects, which GitHub Pages serves from + // their own repositories under hyperlight-dev.github.io. + redirects: { + '/hluk': 'https://hyperlight-dev.github.io/hyperlight-unikraft/', + }, integrations: [ starlight({ title: 'Hyperlight', favicon: '/favicon.png', + customCss: ['./src/styles/custom.css'], + head: [ + { tag: 'link', attrs: { rel: 'preconnect', href: 'https://fonts.googleapis.com' } }, + { tag: 'link', attrs: { rel: 'preconnect', href: 'https://fonts.gstatic.com', crossorigin: true } }, + { + tag: 'link', + attrs: { + rel: 'stylesheet', + href: 'https://fonts.googleapis.com/css2?family=Schibsted+Grotesk:ital,wght@0,400..900;1,400..900&family=JetBrains+Mono:wght@400;600&display=swap', + }, + }, + ], components: { Footer: './src/components/HyperlightFooter.astro' }, diff --git a/src/content/docs/resources/projects/hyperlight-unikraft.mdx b/src/content/docs/resources/projects/hyperlight-unikraft.mdx index d232890..a165426 100644 --- a/src/content/docs/resources/projects/hyperlight-unikraft.mdx +++ b/src/content/docs/resources/projects/hyperlight-unikraft.mdx @@ -1,66 +1,55 @@ --- title: Hyperlight Unikraft -description: Run Unikraft unikernels and Linux applications on Hyperlight micro virtual machines. +description: Run ordinary Linux programs, such as Python, Node.js, .NET, Go and Rust, inside Hyperlight micro virtual machines on a Unikraft kernel. --- import { LinkButton } from '@astrojs/starlight/components'; -Hyperlight Unikraft runs [Unikraft](https://unikraft.org/) unikernels on [Hyperlight](https://github.com/hyperlight-dev/hyperlight), -enabling Linux applications written in Python, Node.js, Go, Rust, C, and C++ to execute inside hardware-isolated -micro virtual machines. +Hyperlight Unikraft runs ordinary Linux programs inside Hyperlight micro virtual machines, using a [Unikraft](https://unikraft.org/) unikernel as the guest kernel. Python, Node.js, .NET, Go, Rust, C, Bash, PowerShell, QuickJS and Wasmtime run unmodified. A guest reaches nothing on the host unless you allow it, and a warmed guest comes back from a snapshot in milliseconds. -It provides a CLI host that loads a Unikraft kernel and optional initrd, passes application arguments into the guest, -and captures console output through Hyperlight. The project also includes ready-to-use example configurations for -building and running common application runtimes. - -Key features include: - -- **Unikernel execution** — Run Linux application binaries inside Unikraft guests on Hyperlight -- **Thin, opt-in host surface** — Guests have no host filesystem, network, or host functions by default; `--mount`, `--net`, and `--enable-tools` opt in through a single `__dispatch` JSON-RPC bridge -- **Broad language support** — Use examples for Python, Node.js, Go, Rust, C, C++, and more -- **Generic command line** — Pass arguments to any application with `-- arg1 arg2 ...` -- **Fast startup** — Use Hyperlight's lightweight VMM for low-latency micro virtual machine startup -- **Host filesystem sandboxing** — Preopen host directories and expose them to guest applications with path isolation - -From commandline: +It ships as a CLI, `hluk` (pronounced "hulk"), and as a Rust library. ```bash -# Install pyhl -cargo install --git https://github.com/hyperlight-dev/hyperlight-unikraft \ - hyperlight-unikraft-host --bin pyhl - -pyhl setup --from examples/python-agent-driver -pyhl run -c 'import pandas as pd; print(pd.DataFrame({"x":[1,2,3]}).sum().to_dict())' +# Linux, macOS +curl -fsSL https://raw.githubusercontent.com/hyperlight-dev/hyperlight-unikraft/main/install.sh | sh +# Windows (PowerShell) +irm https://raw.githubusercontent.com/hyperlight-dev/hyperlight-unikraft/main/install.ps1 | iex + +hluk init hello --template python # pulls the python image +cd hello +hluk run # boots the micro-VM and saves a snapshot +hluk run # restores the snapshot ``` -As a library: +As a library, load code once and call it with JSON, giving it only the host functions you choose: -``` -fn main() -> anyhow::Result<()> { - let code = std::env::args() - .nth(1) - .unwrap_or_else(|| r#"print("hello from the pyhl library API")"#.to_string()); - - let home = std::env::var("PYHL_HOME") - .map(std::path::PathBuf::from) - .unwrap_or_else(|_| Path::new(".pyhl").to_path_buf()); +```rust +use hyperlight_unikraft::SandboxBuilder; +use serde_json::json; - // Default: no mounts. Add `Preopen::new(host, guest)` entries to - // expose host directories via the guest's hostfs. - let mounts: &[Preopen] = &[]; +let mut sandbox = SandboxBuilder::from_initrd("quickjs-rootfs.cpio") + .host_function("db.lookup", |args| { + let [id]: [u32; 1] = + serde_json::from_str(args).map_err(|e| e.to_string())?; + Ok(json!({ "id": id, "name": "Ada" }).to_string()) + }) + .boot()?; - let mut rt = pyhl::Runtime::new(&home, mounts, None, None)?; +sandbox.run(r#" + import { lookup } from "host:db"; + globalThis.greet = (e) => ({ message: `Hello, ${lookup(e.id).name}` }); +"#)?; - eprintln!("-- first run (hermetic from loaded snapshot) --"); - let t1 = rt.run_code(&code)?; - eprintln!("restore={:.1}ms call={:.1}ms", t1.restore_ms, t1.call_ms); +let out = sandbox.call("greet", r#"{"id": 7}"#)?; +``` - eprintln!("-- second run (restores to the same snapshot) --"); - let t2 = rt.run_code(&code)?; - eprintln!("restore={:.1}ms call={:.1}ms", t2.restore_ms, t2.call_ms); +Key features include: - Ok(()) -} -``` +- **Snapshot restore**: boot and warm a guest once, then start from its snapshot in milliseconds. +- **Default-deny host access**: no host files, network or listening ports unless the manifest or a flag grants them. +- **Templates**: `hluk init` starts a project for any supported runtime, and a Dockerfile extends a runtime image with packages. +- **Guest and host function calls**: from the quickjs, node, python, dotnet-jit and wasmtime images. +- **Linux, Windows and macOS hosts**: KVM or MSHV, Windows Hypervisor Platform, and Hypervisor.framework on Apple silicon. -GitHub +Project site +GitHub diff --git a/src/content/docs/resources/projects/index.mdx b/src/content/docs/resources/projects/index.mdx index 45f1fa2..97316f9 100644 --- a/src/content/docs/resources/projects/index.mdx +++ b/src/content/docs/resources/projects/index.mdx @@ -13,7 +13,7 @@ The following projects are part of the Hyperlight family, providing language run - + diff --git a/src/styles/custom.css b/src/styles/custom.css new file mode 100644 index 0000000..853f7c0 --- /dev/null +++ b/src/styles/custom.css @@ -0,0 +1,14 @@ +/* The type of the hyperlight-unikraft site (hyperlight.org/hluk), so the + two read as one site: Schibsted Grotesk for text, JetBrains Mono for + code. Colors stay Starlight's, which that site uses too. */ +:root { + --sl-font: 'Schibsted Grotesk'; + --sl-font-mono: 'JetBrains Mono'; +} + +/* Headings set tight and heavy, as there. */ +#_top, +.sl-markdown-content :is(h1, h2, h3) { + font-weight: 800; + letter-spacing: -0.025em; +}