Skip to content

Repository files navigation

dummie

dummie

Secure computers for everyone.
VM booted in seconds, sealed off from everything else,
and yours for as long as you need it.

Architecture · Layout · License


What this is

dummie hands out sandboxes that are virtual machines. Every guest gets its own kernel, its own filesystem and its own network stack, so code you did not write and cannot trust has nothing to escape into. The kernel is built in-tree and stripped to what a short-lived guest needs, which is what makes cold boot fast enough to sit in a request path.

It is self-hostable end to end: a control plane you run once, and as many hosts as you want behind it.

  • Hardware isolation, not namespaces. A sandbox is a microVM, not a container.
  • Per-run network policy. Pick the domains and ports you want to whitelist for your VM
  • One binary to deploy. Single binary deploy.

Repository layout

Each directory is a project in its own right.

Directory What lives there
control/ The control plane: API, console, migrations, OpenAPI spec, generated SDK. cmd/dclient/ builds the host agent.
backstage/ dproxy and dpipe, the connection services dclient runs on each host, plus dinit, the guest init copied into every rootfs and booted as pid 1.
website/ Landing page, case studies and docs. Prerendered Nuxt with SSR on, shipped as its own container — deliberately separate from the console SPA in control/web-client.

Contributing

This repo is very open to contributions, specifically prompt requests! If you have an idea or improvement, feel free to open an issue describing what you'd like rather than submitting a pull request. We'll take it from there. :)

License

GNU Affero General Public License v3.0.

About

Secure computers for everyone.

Topics

Resources

Stars

4 stars

Watchers

1 watching

Forks

Releases

Packages

Contributors

Languages