Skip to content

BuildNot yet confirmed elsewhere1 publisher3 min readPublished

Firecracker won't run on a Mac, so Encore rebuilt the Linux image toolchain to match

Encore's crackling drives Firecracker on Linux and Apple's hypervisor on macOS. Getting one set of images to boot on both meant re-implementing much of what Docker and a Linux host do for free.

The Engineer · Build desk

How we use AISend a correction

What happened

  • Encore has run every one of its backend builds inside a Firecracker microVM since mid-2022.
  • Firecracker drives KVM and needs a Linux host with /dev/kvm, which no Mac has, and most Encore engineers develop on Macs.
  • For four years, changing the build system meant doing it on a machine other than your own.

Why it matters

  • cost Each guest-side edit was billed as three trips to a remote box: ship the layers, squash them there, restart the container. The engineer paid that toll per iteration, not per release.
  • exposure The development path wrapped Firecracker in a privileged container holding /dev/kvm and /dev/net/tun, so the boundary around the microVM on the dev host was not the boundary production relies on.
  • constraint One shared host means port allocation lives in a gitignored per-engineer file, so the environment cannot be reproduced by cloning the repository and engineers have to negotiate to avoid collisions.
  • precedent Parity with a hypervisor that will not travel now looks like a second maintained backend rather than a patch, which is the bill any other Firecracker shop on Macs should expect to be handed.

The expensive half was never the Go binaries. Those cross-compiled with `GOOS=linux GOARCH=amd64`, rsynced to the build host, and Encore decided whether a restart was needed by counting the transferred files [9]. Images were the problem, because Firecracker boots a block device while Docker produces layers, and Encore says it could not find an existing tool that turned one into the other [10]. So the conversion got written in house: `docker save`, explode the tarball locally, rsync the layers and manifest across, then pipe a shell function into a login shell on the far end and run it there [11].

What that function does is a list of jobs a container runtime normally handles. It re-extracted every layer in manifest order and deleted the `.wh..wh..opq` whiteout markers with `find`, because `tar` will not apply them [12]. It wrote a hardcoded `/etc/resolv.conf`, since the VM had no DNS otherwise [13]. It lifted the image's environment variables out of the Docker config with `jq` [14], then called `mksquashfs` to produce something Firecracker could boot [15]. There was a cache keyed on the Docker image id to skip the whole path on a match [16], which is least useful in the case that matters: the conversion ran whenever anything in the image changed, which was most of the time if you were working on the guest side [17].

Underneath that, the dev host ran Firecracker inside a Docker container, which meant `--privileged` plus `/dev/kvm` and `/dev/net/tun` passed through, because the process inside was going to make tap devices and boot VMs of its own [19]. Firecracker wants those taps on a host bridge, and a container has no host bridge, so a script created a `docker0` bridge and made `eth0` its member before the build service came up [20].

The two spans Encore gives leave no gap between them, so for the entire life of the production hypervisor, nobody worked on the build system on the machine they were typing on [23]. Each engineer instead got a personal user on one shared box in a datacentre, reached over Tailscale [7]. The shell was eventually rewritten in Go, but the pipeline and the host stayed the same [21], which is the tell: this was not a stopgap anybody expected to remove, it was infrastructure.

The fact that carries the story is the declined port. According to Encore, a working proof of concept on Apple's Virtualization.framework existed and the maintainers turned it down [24], so the work of making a Mac boot the same artefact landed on the people who needed it. Encore's answer is a single microVM API over two hypervisors, and the entry fee was rebuilding much of the Linux image toolchain to run on macOS [1]. Firecracker's minimalism is the point of it: only what a Linux kernel needs [3]. The cost of that minimalism does not disappear when a shop runs Macs. It moves into the shop's own repo, where it now has to be maintained twice over.

What to watch

  • Whether crackling is released as a standalone component with a stable API, or stays welded into Encore's build service.
  • Any movement from Firecracker's maintainers on macOS or a non-KVM backend, which would strand the downstream work.
  • Whether the shared datacentre build box gets retired now that laptops can boot the same images, and what happens to the per-engineer port config.

Clarity's read

What the record supports and how the coverage leans. The claims behind it follow.

Reality

Evidence56
Adoption30
Hype gap+12
Incentives68
Confidence60
Why these scores

Claim ledger

Ranked by verification strength, evidence, and original report placement.

  1. [1]

    Encore built crackling, a single microVM API that drives Firecracker on Linux and Apple's hypervisor on macOS; booting the same images on both required rebuilding much of the Linux image toolchain to run on macOS.

  2. [2]

    Encore builds and deploys backend applications, and since mid-2022 every one of those builds has run inside a Firecracker microVM.

    ReportedSupportedView cited source
  3. [3]

    Firecracker strips the emulated hardware down to what a Linux kernel needs, giving each build the isolation of a virtual machine with startup close to the cost of a container.

    ReportedSupportedView cited source

Sources

1 independent publisher whose own reporting we read for this story.

  1. encore.dev

    1 article · August 22, 2026

    We rebuilt the Linux microVM stack on Apple Silicon

Share your take

Let Clarity write the post for you.

Signed-in readers get a short post drafted on this story in the register they choose — narrative, analytical, or a direct position — editable to the last word before it goes anywhere. The share buttons at the top of this story work without an account.

Topics and entities

Follow any of these and your For You feed starts watching them — no settings page required.

Topics

Loading related stories