deniz.in

Markets

Weather

Loading weather

· via Hacker News – Front Page (native)

Docker Desktop has run on microVMs since 2016, engineer explains

A Docker engineer's retrospective explains how Docker Desktop replaced VirtualBox with a minimal embedded microVM in 2016, years before Firecracker made the approach fashionable.

Docker Desktop has run on microVMs since 2016, engineer explains

A blog post by a Docker engineer, currently on the Hacker News front page, makes a claim that reframes a fashionable infrastructure debate: Docker's desktop product has been built on microVMs since 2016, long before the term became a buzzword.

The post on dave.recoil.org is written by an engineer who joined Docker in 2015. It responds to recent interest in microVMs, meaning workloads running on a trimmed-down Linux kernel under a minimal virtual machine monitor such as Firecracker, which AWS announced at re:Invent 2018, on top of a hypervisor like KVM or Xen. MicroVMs are often contrasted with conventional Docker containers and pitched as the more secure option. The author's argument is that Docker itself crossed that line a decade ago.

From VirtualBox to a library VMM

According to the post, the state of the art when the author joined Docker in 2015 was Docker Toolbox, which ran on VirtualBox. VirtualBox was a capable product but shipped far more than Docker needed, including its own graphical interface and its own update process.

Docker wanted its product to feel like a native Mac or Windows application rather than a bundle of parts. Drawing on the Mirage Unikernel libraries, the team built what the post calls a "library VMM": a virtual machine monitor embedded inside the Docker application, built for a single job and designed to be small, secure and fast. The first version was called hyperkit and the current one is Docker VMM. A footnote records a compromise: although the aim was to link everything into one static, unikernel-like process, technical reasons mean there is still a single host process per VM.

The guest side was minimal too. The VM's kernel and root filesystem came from the LinuxKit project, and the post describes today's version as an even leaner variant that is conceptually unchanged, similar to containerd's nerdbox.

What the design delivered in 2016

For Docker for Mac, later renamed Docker Desktop, the microVM approach enabled three things according to the post:

  • Rootless operation on every platform, without depending on Linux's in-guest "rootless" support. Because the entire Linux kernel is treated as untrusted, the author argues that even a Linux kernel CVE does not matter.
  • A minimal device model, with a tightly constrained host/VM interface that is easier to reason about and audit.
  • Straightforward VPN interoperability, which was later extended into enforced network policy such as Registry Access Management.

The same foundation under Docker Sandboxes

In 2026, the post says, this microVM technology underpins not only Docker Desktop but also Docker Sandboxes, a product aimed at running coding agents and their harnesses with strict isolation and governance. The suggested demonstration is installing Docker Sandboxes and running sbx run claude. For the longer history, the post points to a Communications of the ACM article, "A Decade of Docker Containers".

Why it matters

Arguments about containers versus microVMs often place Docker firmly on the shared-kernel side of the divide. According to this account, that has not described Docker's flagship desktop product for roughly a decade: on Mac and Windows, containers have run inside a purpose-built, minimal VM with an untrusted kernel since 2016. The claim covers Docker Desktop rather than the classic Docker Engine on a Linux server, where shared-kernel containers remain the norm. Even so, the history is useful for cloud practitioners evaluating Firecracker-style isolation for CI, multi-tenant platforms or AI coding agents. Docker's decade of production experience with minimal VMMs and LinuxKit-based guests suggests the pattern is mature rather than novel, and Docker is now betting the same foundation on the agent-sandboxing market.

  • #docker
  • #microvm
  • #virtualization
  • #containers
  • #cloud

Related posts