About this project

Hyperlight is a lightweight Virtual Machine Manager (VMM) intended to be embedded as a library inside applications, letting them execute untrusted code inside hypervisor-isolated micro virtual machines. It is a Cloud Native Computing Foundation sandbox project and is currently pre-1.0, so the API may change between releases. How it works: the host application builds a sandbox from a guest binary and calls functions across the VM boundary much like local functions. Guests are purpose-built ELF binaries written in no_std Rust or C, with no guest kernel or operating system, which keeps startup time and memory footprint low. Host and guest communicate through typed function calls, and guests are sandboxed by default with no access to the host filesystem or network. Guest state persists across calls, and snapshot()/restore() can save and reset VM memory so sandboxes can be reused without recreating the VM. Supported hypervisors include KVM, MSHV and the Windows Hypervisor Platform. The README shows a host example that registers a host function and calls into the guest, and a guest example using macros such as #[host_function] and #[guest_function]. Stated use cases include running untrusted or third-party code with hypervisor-level isolation, creating and tearing down sandboxes in milliseconds, making guest function calls in microseconds, embedding sandboxed execution in an application, building functions-as-a-service with hypervisor isolation, and reusing sandboxes via snapshot and restore. The project explicitly says it is not intended for general-purpose virtualization or for running full Linux guest workloads that need syscalls, networking or filesystem access. The repository is organized into host and guest libraries, a C API wrapper, a guest libc built from picolibc, guest and component macros, tracing support, shared common code, FlatBuffer schema definitions, a trace dump tool, and test guest programs in Rust and C. Related projects include cargo-hyperlight for building and scaffolding guests, hyperlight-wasm for WebAssembly modules, hyperlight-js for JavaScript, hyperlight-sandbox for multi-backend sandboxing with Python, .NET and Rust SDKs, and hyperlight-unikraft for running Linux applications using Unikraft as the guest kernel. Documentation, contribution guidelines and community meeting details are provided in the repository.