From 32e9baa802c8e7e47af87bb5a7cae58e814a4b47 Mon Sep 17 00:00:00 2001 From: danbugs Date: Fri, 2 Oct 2026 23:29:29 +0000 Subject: [PATCH 1/3] Redirect /hluk to the hyperlight-unikraft site hyperlight-unikraft's site is a GitHub Pages project site of its own repository, so hyperlight.org can't serve it directly; /hluk sends visitors there. Signed-off-by: danbugs --- astro.config.mjs | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/astro.config.mjs b/astro.config.mjs index a5e71ba..e8b9bd0 100644 --- a/astro.config.mjs +++ b/astro.config.mjs @@ -5,6 +5,11 @@ import starlightBlog from 'starlight-blog'; export default defineConfig({ site: 'https://hyperlight.org', + // Sites of other hyperlight-dev projects, which GitHub Pages serves from + // their own repositories under hyperlight-dev.github.io. + redirects: { + '/hluk': 'https://hyperlight-dev.github.io/hyperlight-unikraft/', + }, integrations: [ starlight({ title: 'Hyperlight', From 107aa20b8b0859ae28f9e36ba1d3c5dbc123728e Mon Sep 17 00:00:00 2001 From: danbugs Date: Fri, 2 Oct 2026 23:29:29 +0000 Subject: [PATCH 2/3] Use the hyperlight-unikraft site's fonts Schibsted Grotesk for text and JetBrains Mono for code, through Starlight's --sl-font and --sl-font-mono, with headings set heavier and tighter. The hyperlight-unikraft site uses these fonts and this site's colors, so moving between the two reads as one site. Signed-off-by: danbugs --- astro.config.mjs | 12 ++++++++++++ src/styles/custom.css | 14 ++++++++++++++ 2 files changed, 26 insertions(+) create mode 100644 src/styles/custom.css diff --git a/astro.config.mjs b/astro.config.mjs index e8b9bd0..4c8d377 100644 --- a/astro.config.mjs +++ b/astro.config.mjs @@ -14,6 +14,18 @@ export default defineConfig({ starlight({ title: 'Hyperlight', favicon: '/favicon.png', + customCss: ['./src/styles/custom.css'], + head: [ + { tag: 'link', attrs: { rel: 'preconnect', href: 'https://fonts.googleapis.com' } }, + { tag: 'link', attrs: { rel: 'preconnect', href: 'https://fonts.gstatic.com', crossorigin: true } }, + { + tag: 'link', + attrs: { + rel: 'stylesheet', + href: 'https://fonts.googleapis.com/css2?family=Schibsted+Grotesk:ital,wght@0,400..900;1,400..900&family=JetBrains+Mono:wght@400;600&display=swap', + }, + }, + ], components: { Footer: './src/components/HyperlightFooter.astro' }, diff --git a/src/styles/custom.css b/src/styles/custom.css new file mode 100644 index 0000000..853f7c0 --- /dev/null +++ b/src/styles/custom.css @@ -0,0 +1,14 @@ +/* The type of the hyperlight-unikraft site (hyperlight.org/hluk), so the + two read as one site: Schibsted Grotesk for text, JetBrains Mono for + code. Colors stay Starlight's, which that site uses too. */ +:root { + --sl-font: 'Schibsted Grotesk'; + --sl-font-mono: 'JetBrains Mono'; +} + +/* Headings set tight and heavy, as there. */ +#_top, +.sl-markdown-content :is(h1, h2, h3) { + font-weight: 800; + letter-spacing: -0.025em; +} From f8a5a3587a986d44f53aa7829c0218b2ddec3fe1 Mon Sep 17 00:00:00 2001 From: danbugs Date: Fri, 2 Oct 2026 23:29:29 +0000 Subject: [PATCH 3/3] Update the Hyperlight Unikraft project page The page described the old pyhl CLI. It now covers the hluk CLI and the Rust library, with install commands for Linux, macOS and Windows, and links to the project site. Signed-off-by: danbugs --- .../projects/hyperlight-unikraft.mdx | 85 ++++++++----------- src/content/docs/resources/projects/index.mdx | 2 +- 2 files changed, 38 insertions(+), 49 deletions(-) diff --git a/src/content/docs/resources/projects/hyperlight-unikraft.mdx b/src/content/docs/resources/projects/hyperlight-unikraft.mdx index d232890..a165426 100644 --- a/src/content/docs/resources/projects/hyperlight-unikraft.mdx +++ b/src/content/docs/resources/projects/hyperlight-unikraft.mdx @@ -1,66 +1,55 @@ --- title: Hyperlight Unikraft -description: Run Unikraft unikernels and Linux applications on Hyperlight micro virtual machines. +description: Run ordinary Linux programs, such as Python, Node.js, .NET, Go and Rust, inside Hyperlight micro virtual machines on a Unikraft kernel. --- import { LinkButton } from '@astrojs/starlight/components'; -Hyperlight Unikraft runs [Unikraft](https://unikraft.org/) unikernels on [Hyperlight](https://github.com/hyperlight-dev/hyperlight), -enabling Linux applications written in Python, Node.js, Go, Rust, C, and C++ to execute inside hardware-isolated -micro virtual machines. +Hyperlight Unikraft runs ordinary Linux programs inside Hyperlight micro virtual machines, using a [Unikraft](https://unikraft.org/) unikernel as the guest kernel. Python, Node.js, .NET, Go, Rust, C, Bash, PowerShell, QuickJS and Wasmtime run unmodified. A guest reaches nothing on the host unless you allow it, and a warmed guest comes back from a snapshot in milliseconds. -It provides a CLI host that loads a Unikraft kernel and optional initrd, passes application arguments into the guest, -and captures console output through Hyperlight. The project also includes ready-to-use example configurations for -building and running common application runtimes. - -Key features include: - -- **Unikernel execution** — Run Linux application binaries inside Unikraft guests on Hyperlight -- **Thin, opt-in host surface** — Guests have no host filesystem, network, or host functions by default; `--mount`, `--net`, and `--enable-tools` opt in through a single `__dispatch` JSON-RPC bridge -- **Broad language support** — Use examples for Python, Node.js, Go, Rust, C, C++, and more -- **Generic command line** — Pass arguments to any application with `-- arg1 arg2 ...` -- **Fast startup** — Use Hyperlight's lightweight VMM for low-latency micro virtual machine startup -- **Host filesystem sandboxing** — Preopen host directories and expose them to guest applications with path isolation - -From commandline: +It ships as a CLI, `hluk` (pronounced "hulk"), and as a Rust library. ```bash -# Install pyhl -cargo install --git https://github.com/hyperlight-dev/hyperlight-unikraft \ - hyperlight-unikraft-host --bin pyhl - -pyhl setup --from examples/python-agent-driver -pyhl run -c 'import pandas as pd; print(pd.DataFrame({"x":[1,2,3]}).sum().to_dict())' +# Linux, macOS +curl -fsSL https://raw.githubusercontent.com/hyperlight-dev/hyperlight-unikraft/main/install.sh | sh +# Windows (PowerShell) +irm https://raw.githubusercontent.com/hyperlight-dev/hyperlight-unikraft/main/install.ps1 | iex + +hluk init hello --template python # pulls the python image +cd hello +hluk run # boots the micro-VM and saves a snapshot +hluk run # restores the snapshot ``` -As a library: +As a library, load code once and call it with JSON, giving it only the host functions you choose: -``` -fn main() -> anyhow::Result<()> { - let code = std::env::args() - .nth(1) - .unwrap_or_else(|| r#"print("hello from the pyhl library API")"#.to_string()); - - let home = std::env::var("PYHL_HOME") - .map(std::path::PathBuf::from) - .unwrap_or_else(|_| Path::new(".pyhl").to_path_buf()); +```rust +use hyperlight_unikraft::SandboxBuilder; +use serde_json::json; - // Default: no mounts. Add `Preopen::new(host, guest)` entries to - // expose host directories via the guest's hostfs. - let mounts: &[Preopen] = &[]; +let mut sandbox = SandboxBuilder::from_initrd("quickjs-rootfs.cpio") + .host_function("db.lookup", |args| { + let [id]: [u32; 1] = + serde_json::from_str(args).map_err(|e| e.to_string())?; + Ok(json!({ "id": id, "name": "Ada" }).to_string()) + }) + .boot()?; - let mut rt = pyhl::Runtime::new(&home, mounts, None, None)?; +sandbox.run(r#" + import { lookup } from "host:db"; + globalThis.greet = (e) => ({ message: `Hello, ${lookup(e.id).name}` }); +"#)?; - eprintln!("-- first run (hermetic from loaded snapshot) --"); - let t1 = rt.run_code(&code)?; - eprintln!("restore={:.1}ms call={:.1}ms", t1.restore_ms, t1.call_ms); +let out = sandbox.call("greet", r#"{"id": 7}"#)?; +``` - eprintln!("-- second run (restores to the same snapshot) --"); - let t2 = rt.run_code(&code)?; - eprintln!("restore={:.1}ms call={:.1}ms", t2.restore_ms, t2.call_ms); +Key features include: - Ok(()) -} -``` +- **Snapshot restore**: boot and warm a guest once, then start from its snapshot in milliseconds. +- **Default-deny host access**: no host files, network or listening ports unless the manifest or a flag grants them. +- **Templates**: `hluk init` starts a project for any supported runtime, and a Dockerfile extends a runtime image with packages. +- **Guest and host function calls**: from the quickjs, node, python, dotnet-jit and wasmtime images. +- **Linux, Windows and macOS hosts**: KVM or MSHV, Windows Hypervisor Platform, and Hypervisor.framework on Apple silicon. -GitHub +Project site +GitHub diff --git a/src/content/docs/resources/projects/index.mdx b/src/content/docs/resources/projects/index.mdx index 45f1fa2..97316f9 100644 --- a/src/content/docs/resources/projects/index.mdx +++ b/src/content/docs/resources/projects/index.mdx @@ -13,7 +13,7 @@ The following projects are part of the Hyperlight family, providing language run - +