As far as I know, Firecracker, gVisor, and Kata Containers are the solution here. They use VM primitives (x64_64 and ARM64 extensions) and have lighter codebases<p><a href="https://firecracker-microvm.github.io/" rel="nofollow">https://firecracker-microvm.github.io/</a><p><a href="https://gvisor.dev/" rel="nofollow">https://gvisor.dev/</a><p><a href="https://katacontainers.io/" rel="nofollow">https://katacontainers.io/</a><p>But I don't have any direct experience with any of them. I'd be curious what people who have built on top of them think<p>edit: OK it looks like Kata can use Firecracker, so as far as isolation, it's either Firecracker or gVisor. And Firecracker is the VMM I mentioned, but gVisor is quite different -- it's more like a user space kernel that emulates syscalls.
I'm going to toss in smolvm as well because firecracker needs some expertise to make the box usable and secure.<p><a href="https://github.com/smol-machines/smolvm" rel="nofollow">https://github.com/smol-machines/smolvm</a>
As I understand it Kata supports multiple VMM backends, Firecracker, QEmu, Cloud Hypervisor, and their own Dragonball. Except QEmu, I believe those are all built on crates in the rust-vmm ecosystem, each making slightly different tradeoffs.