# virtual machines

Published articles for virtual machines.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## Security evaluations find traditional virtual machines inadequate for containing cyber-capable autonomous agents

DevFeed: [Security evaluations find traditional virtual machines inadequate for containing cyber-capable autonomous agents](<https://devfeed.tech/articles/repeated-vm-escapes-by-gpt-5-6-cyber-based-agents-prove-vms-and-os-require-better-maintenance-41295.md>)

Original publisher: [Read original article](<https://www.infoq.com/news/2026/09/agent-escape-vm/>)

Author: Olimpiu Pop

Published: 2026-09-17T07:07:00Z

Content type: news

Language: en

Sources: [InfoQ](<https://devfeed.tech/sources/infoq.md>)

Topics: [virtual machines](<https://devfeed.tech/topics/virtual-machines.md>), [Security](<https://devfeed.tech/topics/security.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Linux Kernel](<https://devfeed.tech/topics/linux-kernel.md>), [qemu](<https://devfeed.tech/topics/qemu.md>), [Firecracker](<https://devfeed.tech/topics/firecracker.md>), [systems](<https://devfeed.tech/topics/systems.md>)

Tags: [agent-escape-vm](<https://devfeed.tech/tags/agent-escape-vm.md>), [ai-security](<https://devfeed.tech/tags/ai-security.md>), [development](<https://devfeed.tech/tags/development.md>), [devops](<https://devfeed.tech/tags/devops.md>), [firecracker](<https://devfeed.tech/tags/firecracker.md>), [linux](<https://devfeed.tech/tags/linux.md>), [linux-kernel](<https://devfeed.tech/tags/linux-kernel.md>), [news](<https://devfeed.tech/tags/news.md>), [qemu](<https://devfeed.tech/tags/qemu.md>), [security](<https://devfeed.tech/tags/security.md>), [security-breach](<https://devfeed.tech/tags/security-breach.md>), [virtual-machines](<https://devfeed.tech/tags/virtual-machines.md>), [virtualization](<https://devfeed.tech/tags/virtualization.md>), [vm](<https://devfeed.tech/tags/vm.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

Security evaluations found that a cyber-capable autonomous agent escaped standard QEMU and KVM virtual machine configurations by exploiting kernel and library vulnerabilities. Firecracker contained the agent in testing, but the agent still hardlocked the host through Linux kernel flaws.

### Source excerpt

Traditional virtual machines are inadequate for isolating cyber-capable autonomous agents. Tests using GPT-5.6-Cyber indicated multiple escape attempts due to kernel flaws. While Firecracker provided some containment, vulnerabilities remained. The study underscores the need for minimal attack surface virtualisation technologies and rapid, proactive patching strategies to safeguard host systems. By Olimpiu Pop

## How vagrant-libvirt Plugin Deals with Duplicate Subnets

DevFeed: [How vagrant-libvirt Plugin Deals with Duplicate Subnets](<https://devfeed.tech/articles/how-vagrant-libvirt-plugin-deals-with-duplicate-subnets-26994.md>)

Original publisher: [Read original article](<https://blog.ipspace.net/2026/09/vagrant-libvirt-duplicate-subnets/>)

Published: 2026-09-16T06:27:00Z

Content type: tutorial

Language: en

Sources: [ipSpace.net blog](<https://devfeed.tech/sources/ipspace-net-blog.md>)

Topics: [Vagrant](<https://devfeed.tech/topics/vagrant.md>), [virtual machines](<https://devfeed.tech/topics/virtual-machines.md>), [Linux](<https://devfeed.tech/topics/linux.md>), [Ubuntu](<https://devfeed.tech/topics/ubuntu.md>)

Tags: [debugging](<https://devfeed.tech/tags/debugging.md>), [linux](<https://devfeed.tech/tags/linux.md>), [vagrant](<https://devfeed.tech/tags/vagrant.md>), [virtual-machines](<https://devfeed.tech/tags/virtual-machines.md>), [virtualization](<https://devfeed.tech/tags/virtualization.md>)

### AI overview

The article explains that vagrant-libvirt can fail when an existing libvirt virtual network has the same IP subnet as the desired management network but a different name. It identifies the resulting network-name mismatch and reports that correcting the network definition in the Vagrantfile resolves the problem.

### Source excerpt

TL&DR: Badly. The vagrant-libvirt plugin mysteriously crashes when an existing virtual network (with a different libvirt name) uses the same IP subnet as the desired management network. Background: netlab is using the vagrant-libvirt plugin to manage libvirt/KVM virtual machines with Vagrant. As I already have that infrastructure, I use it to start standalone virtual machines (usually to test various Ubuntu releases) on my Linux server. Things work great... until they don't. Here's how I managed to waste half a day chasing imaginary gremlins caused by a simple error. Read more ...

## AMD Preparing Linux For Enhanced SMT Protection "ESMTP" For EPYC VMs

DevFeed: [AMD Preparing Linux For Enhanced SMT Protection "ESMTP" For EPYC VMs](<https://devfeed.tech/articles/amd-preparing-linux-for-enhanced-smt-protection-esmtp-for-epyc-vms-17440.md>)

Original publisher: [Read original article](<https://www.phoronix.com/news/AMD-Enhanced-SMT-Protection>)

Author: Michael Larabel

Published: 2026-09-14T18:03:38Z

Content type: news

Language: en

Sources: [Phoronix](<https://devfeed.tech/sources/phoronix.md>)

Topics: [Linux](<https://devfeed.tech/topics/linux.md>), [Security](<https://devfeed.tech/topics/security.md>), [Hardware](<https://devfeed.tech/topics/hardware.md>), [cpu](<https://devfeed.tech/topics/cpu.md>), [Server](<https://devfeed.tech/topics/server.md>), [Cloud](<https://devfeed.tech/topics/cloud.md>)

Tags: [attacks](<https://devfeed.tech/tags/attacks.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [desktop-linux](<https://devfeed.tech/tags/desktop-linux.md>), [hardware](<https://devfeed.tech/tags/hardware.md>), [kernel](<https://devfeed.tech/tags/kernel.md>), [linux](<https://devfeed.tech/tags/linux.md>), [linux-benchmarking](<https://devfeed.tech/tags/linux-benchmarking.md>), [linux-hardware-benchmarks](<https://devfeed.tech/tags/linux-hardware-benchmarks.md>), [linux-hardware-reviews](<https://devfeed.tech/tags/linux-hardware-reviews.md>), [linux-how-to](<https://devfeed.tech/tags/linux-how-to.md>), [linux-performance](<https://devfeed.tech/tags/linux-performance.md>), [linux-server-benchmarks](<https://devfeed.tech/tags/linux-server-benchmarks.md>), [open-source-graphics](<https://devfeed.tech/tags/open-source-graphics.md>), [performance](<https://devfeed.tech/tags/performance.md>), [phoronix](<https://devfeed.tech/tags/phoronix.md>), [phoronix-test-suite](<https://devfeed.tech/tags/phoronix-test-suite.md>), [processors](<https://devfeed.tech/tags/processors.md>), [security](<https://devfeed.tech/tags/security.md>), [server](<https://devfeed.tech/tags/server.md>), [ubuntu-benchmarks](<https://devfeed.tech/tags/ubuntu-benchmarks.md>), [ubuntu-hardware](<https://devfeed.tech/tags/ubuntu-hardware.md>), [virtual-machines](<https://devfeed.tech/tags/virtual-machines.md>)

### AI overview

AMD engineers are preparing Linux kernel support for Enhanced SMT Protection (ESMTP), a hardware-enforced security feature for EPYC virtual machines using SEV-SNP. ESMTP restricts simultaneous multithreading sibling threads to trusted vCPUs from the same guest or idle host threads, reducing side-channel risks from untrusted host or guest workloads. Support is also needed in QEMU and OVMF, and the feature is opt-in because it has a performance cost.

### Source excerpt

AMD engineers today sent out patches on the Linux kernel mailing list for beginning to enable Enhanced SMT Protection "ESMTP" for better security with virtual machines running atop EPYC server processors with SEV-SNP...

## Red Hat edge platforms: Choosing the right one for your use case

DevFeed: [Red Hat edge platforms: Choosing the right one for your use case](<https://devfeed.tech/articles/red-hat-edge-platforms-choosing-the-right-one-for-your-use-case-12354.md>)

Original publisher: [Read original article](<https://developers.redhat.com/articles/2026/09/11/red-hat-edge-platforms-choosing-right-one-your-use-case>)

Author: Daniel Froehlich

Published: 2026-09-11T13:01:48Z

Content type: article

Language: en

Sources: [Red Hat](<https://devfeed.tech/sources/red-hat.md>), [Red Hat Developer](<https://devfeed.tech/sources/red-hat-developer.md>)

Topics: [Edge](<https://devfeed.tech/topics/edge.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [Kubernetes](<https://devfeed.tech/topics/kubernetes.md>), [Architecture & Design](<https://devfeed.tech/topics/architecture-design.md>), [Hardware](<https://devfeed.tech/topics/hardware.md>), [Availability](<https://devfeed.tech/topics/availability.md>), [Microservice](<https://devfeed.tech/topics/microservice.md>)

Tags: [containers](<https://devfeed.tech/tags/containers.md>), [deployment](<https://devfeed.tech/tags/deployment.md>), [edge](<https://devfeed.tech/tags/edge.md>), [edge-computing](<https://devfeed.tech/tags/edge-computing.md>), [hardware](<https://devfeed.tech/tags/hardware.md>), [high-availability](<https://devfeed.tech/tags/high-availability.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [management-tools](<https://devfeed.tech/tags/management-tools.md>), [microservices](<https://devfeed.tech/tags/microservices.md>), [red-hat](<https://devfeed.tech/tags/red-hat.md>), [virtual-machines](<https://devfeed.tech/tags/virtual-machines.md>)

### AI overview

This article introduces a series about choosing Red Hat edge platforms for specific deployment needs. It compares Red Hat Enterprise Linux and Red Hat OpenShift across workload types, platform sizes, hardware requirements, Kubernetes use cases, availability, storage, and management needs.

### Source excerpt

Choosing the right platform for an edge deployment is one of the most consequential decisions an organization makes--and one of the most confusing. The options range from a single-board computer running a handful of containers to a full Kubernetes cluster with high availability, software-defined storage, and centralized management. Pick too small, and you hit a wall when requirements grow. The post Red Hat edge platforms: Choosing the right one for your use case appeared first on Red Hat Developer.

## Cursor Cloud Agents can now run in Vercel Sandbox

DevFeed: [Cursor Cloud Agents can now run in Vercel Sandbox](<https://devfeed.tech/articles/cursor-cloud-agents-can-now-run-in-vercel-sandbox-1075.md>)

Original publisher: [Read original article](<https://vercel.com/changelog/run-cursor-cloud-agents-vercel-sandbox>)

Author: Allen Zhou

Published: 2026-09-03T15:00:00Z

Content type: release

Language: en

Sources: [Vercel News](<https://devfeed.tech/sources/vercel-news.md>)

Topics: [cursor](<https://devfeed.tech/topics/cursor.md>), [Vercel](<https://devfeed.tech/topics/vercel.md>), [Agent Harness](<https://devfeed.tech/topics/agent-harness.md>), [Firecracker](<https://devfeed.tech/topics/firecracker.md>)

Tags: [agents](<https://devfeed.tech/tags/agents.md>), [apis](<https://devfeed.tech/tags/apis.md>), [architecture](<https://devfeed.tech/tags/architecture.md>), [cursor](<https://devfeed.tech/tags/cursor.md>), [enterprise](<https://devfeed.tech/tags/enterprise.md>), [firecracker](<https://devfeed.tech/tags/firecracker.md>), [guide](<https://devfeed.tech/tags/guide.md>), [sandbox](<https://devfeed.tech/tags/sandbox.md>), [scale](<https://devfeed.tech/tags/scale.md>), [vercel](<https://devfeed.tech/tags/vercel.md>), [virtual-machines](<https://devfeed.tech/tags/virtual-machines.md>), [workflows](<https://devfeed.tech/tags/workflows.md>)

### AI overview

Cursor Cloud Agents can run in Vercel Sandbox, using isolated Firecracker microVMs as their execution environment. The architecture combines Cursor's agent harness and inference loop with Vercel Functions and Workflows for durable request handling, worker provisioning, monitoring, retries, cleanup, and short-lived user-scoped credentials.

### Source excerpt

Cursor Cloud Agents can now run in Vercel Sandbox instead of Cursor's hosted machines. Cursor manages the agent harness and inference loop. Its Self-Hosted Machines APIs let you supply the execution environment where agents clone repositories, edit files, and run commands and tests. Self-Hosted Machines requires a Cursor Enterprise plan. Vercel Sandbox provides that execution environment as an isolated Firecracker microVM for each agent request. Vercel Functions and Vercel Workflows form a durable control plane that claims queued agent requests, provisions workers, monitors sessions, and cleans up automatically. With this architecture, you get: A scale-to-zero worker pool without long-lived virtual machines A dedicated, isolated Sandbox for every agent request Durable retries when a worker or session fails Short-lived, user-scoped credentials inside each Sandbox Follow the step-by-step guide to deploy the reference implementation to your own Vercel account, or learn more in the Vercel Sandbox documentation. Read more

## Networking Aspects of Running VMs in Containers

DevFeed: [Networking Aspects of Running VMs in Containers](<https://devfeed.tech/articles/networking-aspects-of-running-vms-in-containers-11436.md>)

Original publisher: [Read original article](<https://blog.ipspace.net/2026/09/running-virtual-machines-in-containers/>)

Published: 2026-09-02T05:44:00Z

Content type: article

Language: en

Sources: [ipSpace.net blog](<https://devfeed.tech/sources/ipspace-net-blog.md>)

Topics: [Containers](<https://devfeed.tech/topics/containers.md>), [virtualization](<https://devfeed.tech/topics/virtualization.md>), [networking](<https://devfeed.tech/topics/networking.md>), [Linux](<https://devfeed.tech/topics/linux.md>), [Orchestration](<https://devfeed.tech/topics/orchestration.md>)

Tags: [bridge](<https://devfeed.tech/tags/bridge.md>), [containers](<https://devfeed.tech/tags/containers.md>), [docker](<https://devfeed.tech/tags/docker.md>), [ethernet](<https://devfeed.tech/tags/ethernet.md>), [linux](<https://devfeed.tech/tags/linux.md>), [netlab](<https://devfeed.tech/tags/netlab.md>), [networking](<https://devfeed.tech/tags/networking.md>), [podman](<https://devfeed.tech/tags/podman.md>), [qemu](<https://devfeed.tech/tags/qemu.md>), [virtual-machines](<https://devfeed.tech/tags/virtual-machines.md>), [virtualization](<https://devfeed.tech/tags/virtualization.md>)

### AI overview

The article explains how vrnetlab and a containerlab fork package virtual machines, especially network devices, as containers so container orchestration can provision network topologies. It focuses on connecting QEMU virtual network interfaces, Linux tap interfaces, bridges, and container veth pairs, including why data-plane and management interfaces require different handling.

### Source excerpt

The vrnetlab project and its containerlab fork implement a wonderful idea: let's package virtual machines (primarily network devices that cannot be containerized) as containers to use reliable orchestration tools like containerlab to provision network topologies. That approach might have a few drawbacks (depending on how the container images are built), but the obvious elephant in the room is: how do you make the virtual network plumbing work? Read more ...

## UniFi ENAS vs 45Drives X15: Comparing Two Rackmount NAS Systems

DevFeed: [UniFi ENAS vs 45Drives X15: Comparing Two Rackmount NAS Systems](<https://devfeed.tech/articles/unifi-enas-vs-45drives-x15-business-vs-pleasure-17367.md>)

Original publisher: [Read original article](<https://nascompares.com/2026/08/31/unifi-enas-vs-45drives-x15-business-vs-pleasure/>)

Author: Rob Andrews

Published: 2026-08-31T16:00:55Z

Content type: comparison

Language: en

Sources: [NAS Compares](<https://devfeed.tech/sources/nas-compares.md>)

Topics: [Enterprise NAS](<https://devfeed.tech/topics/enterprise-nas.md>), [Hardware](<https://devfeed.tech/topics/hardware.md>), [Self-hosted](<https://devfeed.tech/topics/self-hosted.md>), [Ubiquiti](<https://devfeed.tech/topics/ubiquiti.md>), [Server](<https://devfeed.tech/topics/server.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [virtual machines](<https://devfeed.tech/topics/virtual-machines.md>)

Tags: [45-drives](<https://devfeed.tech/tags/45-drives.md>), [45-drives-2026](<https://devfeed.tech/tags/45-drives-2026.md>), [45-drives-2027](<https://devfeed.tech/tags/45-drives-2027.md>), [45-drives-nas](<https://devfeed.tech/tags/45-drives-nas.md>), [45drives](<https://devfeed.tech/tags/45drives.md>), [45drives-2026](<https://devfeed.tech/tags/45drives-2026.md>), [45drives-2027](<https://devfeed.tech/tags/45drives-2027.md>), [45drives-nas](<https://devfeed.tech/tags/45drives-nas.md>), [45drives-review](<https://devfeed.tech/tags/45drives-review.md>), [45drives-system](<https://devfeed.tech/tags/45drives-system.md>), [45drives-unraid](<https://devfeed.tech/tags/45drives-unraid.md>), [45drives-vs-cloud](<https://devfeed.tech/tags/45drives-vs-cloud.md>), [45drives-vs-netapp](<https://devfeed.tech/tags/45drives-vs-netapp.md>), [45drives-vs-qnap](<https://devfeed.tech/tags/45drives-vs-qnap.md>), [45drives-vs-synology](<https://devfeed.tech/tags/45drives-vs-synology.md>), [45drives-vs-unifi](<https://devfeed.tech/tags/45drives-vs-unifi.md>), [45drives-x15](<https://devfeed.tech/tags/45drives-x15.md>), [45drives-x15-vs-unifi-enas](<https://devfeed.tech/tags/45drives-x15-vs-unifi-enas.md>), [comparison](<https://devfeed.tech/tags/comparison.md>), [containers](<https://devfeed.tech/tags/containers.md>), [enterprise-nas](<https://devfeed.tech/tags/enterprise-nas.md>), [hardware](<https://devfeed.tech/tags/hardware.md>), [nas](<https://devfeed.tech/tags/nas.md>), [network-attached-storage-nas](<https://devfeed.tech/tags/network-attached-storage-nas.md>), [self-hosting](<https://devfeed.tech/tags/self-hosting.md>), [ubiquiti](<https://devfeed.tech/tags/ubiquiti.md>), [uncategorised](<https://devfeed.tech/tags/uncategorised.md>), [unifi](<https://devfeed.tech/tags/unifi.md>), [unifi-2026](<https://devfeed.tech/tags/unifi-2026.md>), [unifi-2027](<https://devfeed.tech/tags/unifi-2027.md>), [unifi-enas](<https://devfeed.tech/tags/unifi-enas.md>), [unifi-enas-review](<https://devfeed.tech/tags/unifi-enas-review.md>), [unifi-nas](<https://devfeed.tech/tags/unifi-nas.md>), [unifi-nas-comparison](<https://devfeed.tech/tags/unifi-nas-comparison.md>), [unifi-nas-review](<https://devfeed.tech/tags/unifi-nas-review.md>), [unifi-review](<https://devfeed.tech/tags/unifi-review.md>), [unifi-unas](<https://devfeed.tech/tags/unifi-unas.md>), [virtual-machines](<https://devfeed.tech/tags/virtual-machines.md>)

### AI overview

This comparison examines the UniFi ENAS and 45HomeLab X15 rackmount NAS systems, covering their hardware, storage architectures, connectivity, operating-system services, management models, and upgrade paths. It presents the ENAS as a centrally managed UniFi Drive and ZFS appliance, while the X15 combines a 45Drives chassis with an x86 workstation platform and a lifetime Unraid licence for broader self-hosting and homelab use.

### Source excerpt

UniFi vs 45Drives NAS Servers for Business.- Which Should You Buy? The UniFi ENAS and 45HomeLab X15 sit in a relatively narrow part of the storage market, positioned above conventional desktop NAS systems but below many fully configured enterprise storage platforms. Both are sold without storage media, use rackmount steel enclosures, provide at least 15 [...]

## AAOS SDV - Secure by Design

DevFeed: [AAOS SDV - Secure by Design](<https://devfeed.tech/articles/aaos-sdv-secure-by-design-22687.md>)

Original publisher: [Read original article](<http://android-developers.googleblog.com/2026/08/aaos-sdv-secure-by-design.html>)

Author: Android Developers (noreply@blogger.com)

Published: 2026-08-24T16:00:31Z

Content type: article

Language: en

Sources: [Android Developers Blog](<https://devfeed.tech/sources/android-developers-blog-3.md>)

Topics: [Android](<https://devfeed.tech/topics/android.md>), [Security](<https://devfeed.tech/topics/security.md>), [virtualization](<https://devfeed.tech/topics/virtualization.md>), [virtual machines](<https://devfeed.tech/topics/virtual-machines.md>), [SELinux](<https://devfeed.tech/topics/selinux.md>), [POSIX](<https://devfeed.tech/topics/posix.md>), [Processes](<https://devfeed.tech/topics/processes.md>), [Google](<https://devfeed.tech/topics/google.md>)

Tags: [android](<https://devfeed.tech/tags/android.md>), [android-security](<https://devfeed.tech/tags/android-security.md>), [article](<https://devfeed.tech/tags/article.md>), [google](<https://devfeed.tech/tags/google.md>), [posix](<https://devfeed.tech/tags/posix.md>), [process](<https://devfeed.tech/tags/process.md>), [security](<https://devfeed.tech/tags/security.md>), [selinux](<https://devfeed.tech/tags/selinux.md>), [virtual-machines](<https://devfeed.tech/tags/virtual-machines.md>), [virtualization](<https://devfeed.tech/tags/virtualization.md>)

### AI overview

This article explains the security design of Android Automotive Operating System for Software Defined Vehicle (AAOS SDV). It describes virtualization for domain isolation, UID-based application and service sandboxing, POSIX capabilities, SELinux deny-by-default enforcement, and Android's vulnerability management and disclosure processes.

### Source excerpt

Posted by Markus Vill, Software Engineer, Sean Keys, Security Engineer, and Istvan Nador, Software Engineer, Android Auto At Google, we believe our products should be secure by design, which is why we built the Android Automotive Operating System for Software Defined Vehicle (AAOS SDV) on existing, market-proven platforms, leveraging virtualization technologies like Cuttlefish. While our release announcements focused on the features, this blog post outlines some of the security concepts. Foundation: Domain IsolationVirtualization to isolate co-hosted instances The current trend of consolidating Electronic Control Units (ECUs) into a single chip reduces isolation by running multiple domains side-by-side. While AAOS SDV instances provide internal isolation mechanisms, it is often preferable to run logical domains independently. For instance, a cluster and an infotainment system have distinct requirements. We use virtual machines to run multiple instances in parallel, ensuring that sharing remains explicit and isolation is the default behavior. Inherited Android Security AAOS SDV evolved from Microdroid, a minimalistic Android version optimized for privacy virtual machines (pVM). This lineage provides Android platform engineers with established security features they already know. Process Isolation & Deny by Default AAOS SDV follows Android's User ID (UID)-based isolation model to set up a sandbox for each application. Each service runs in a dedicated process with a unique UID to manage access rights, data directories, and other restrictions. We employ Portable Operating System Interface (POSIX) capabilities to strictly limit operations and pair this with Security-Enhanced Linux (SELinux) to enforce a "deny-by-default" posture. This approach restricts each service to the absolute minimum required, meaning missing configurations block access rather than creating an over-permissive system. We apply this same strategy to our communication permission system, as explained l

## Compiling to intermediate representation: Write yourself a compiler, Part III

DevFeed: [Compiling to intermediate representation: Write yourself a compiler, Part III](<https://devfeed.tech/articles/compiling-to-intermediate-representation-write-yourself-a-compiler-part-iii-38039.md>)

Original publisher: [Read original article](<https://nurkiewicz.com/2026/08/compiling-to-intermediate-representation-write-yourself-a-compiler.html>)

Published: 2026-08-16T22:00:00Z

Content type: tutorial

Language: en

Sources: [Tomasz Nurkiewicz around Java and concurrency](<https://devfeed.tech/sources/tomasz-nurkiewicz-around-java-and-concurrency.md>)

Topics: [Compiler](<https://devfeed.tech/topics/compiler.md>), [virtual machines](<https://devfeed.tech/topics/virtual-machines.md>), [Code](<https://devfeed.tech/topics/code.md>), [WebAssembly](<https://devfeed.tech/topics/web-assembly.md>), [Java](<https://devfeed.tech/topics/java.md>)

Tags: [assembly](<https://devfeed.tech/tags/assembly.md>), [bytecode](<https://devfeed.tech/tags/bytecode.md>), [compilation](<https://devfeed.tech/tags/compilation.md>), [compiler](<https://devfeed.tech/tags/compiler.md>), [go](<https://devfeed.tech/tags/go.md>), [interpreter](<https://devfeed.tech/tags/interpreter.md>), [ir](<https://devfeed.tech/tags/ir.md>), [javascript](<https://devfeed.tech/tags/javascript.md>), [python](<https://devfeed.tech/tags/python.md>), [virtual-machines](<https://devfeed.tech/tags/virtual-machines.md>), [webassembly](<https://devfeed.tech/tags/webassembly.md>), [writing-compiler](<https://devfeed.tech/tags/writing-compiler.md>)

### AI overview

This tutorial explains how a small interpreter project evolves into a compiler by emitting intermediate representation (IR). It contrasts interpreted and compiled languages, describes bytecode and virtual machines, and uses Java and WebAssembly examples to show how IR instructions are executed.

### Source excerpt

It's time to dive a bit deeper and abandon the naive realm of interpreters. Our tiny little project can finally call itself a compiler. In this part we'll emit so-called intermediate representation instead of just evaluating and running the source code as-is. OK, what does this all mean?

## The Pulse: Bending Spoons' Acquisition Strategy

DevFeed: [The Pulse: Bending Spoons' Acquisition Strategy](<https://devfeed.tech/articles/the-pulse-bending-spoons-acquisition-strategy-40922.md>)

Original publisher: [Read original article](<https://blog.pragmaticengineer.com/the-pulse-bending-spoons-acquisition-strategy/>)

Author: Gergely Orosz

Published: 2026-08-05T11:45:13Z

Content type: opinion

Language: en

Sources: [The Pragmatic Engineer](<https://devfeed.tech/sources/the-pragmatic-engineer-2.md>)

Topics: [migration](<https://devfeed.tech/topics/migration.md>), [Architecture & Design](<https://devfeed.tech/topics/architecture-design.md>), [Microservices](<https://devfeed.tech/topics/microservices.md>), [Java](<https://devfeed.tech/topics/java.md>), [virtual machines](<https://devfeed.tech/topics/virtual-machines.md>), [Cloud](<https://devfeed.tech/topics/cloud.md>), [Google Cloud Platform (GCP)](<https://devfeed.tech/topics/google-cloud.md>), [legacy application](<https://devfeed.tech/topics/legacy-application.md>)

Tags: [architecture](<https://devfeed.tech/tags/architecture.md>), [backend](<https://devfeed.tech/tags/backend.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [google-cloud](<https://devfeed.tech/tags/google-cloud.md>), [java](<https://devfeed.tech/tags/java.md>), [legacy](<https://devfeed.tech/tags/legacy.md>), [microservices](<https://devfeed.tech/tags/microservices.md>), [migration](<https://devfeed.tech/tags/migration.md>), [performance](<https://devfeed.tech/tags/performance.md>), [provisioning](<https://devfeed.tech/tags/provisioning.md>), [virtual-machines](<https://devfeed.tech/tags/virtual-machines.md>)

### AI overview

The article examines Bending Spoons' acquisition strategy, including its announced $1.285 billion cash purchase of Airtable and its approach to operating struggling products with smaller teams. It also describes the company's reported modernization of Evernote from a Java 11 monolith running across 750 manually provisioned virtual machines on Google Cloud to a managed-database and microservices architecture in about six months, with reported improvements in performance, reliability, operating cost, and on-call load.

### Source excerpt

In only 5 years, Hopin went from zero to a $7.7B valuation, and back to zero again. Also: Bending Spoons' startup acquisition model.

## The hyperscale blueprint: Why cloud giants prioritize VMs for Kubernetes over bare metal

DevFeed: [The hyperscale blueprint: Why cloud giants prioritize VMs for Kubernetes over bare metal](<https://devfeed.tech/articles/the-hyperscale-blueprint-why-cloud-giants-prioritize-vms-for-kubernetes-over-bare-metal-12238.md>)

Original publisher: [Read original article](<https://platformengineering.org/blog/the-hyperscale-blueprint-why-cloud-giants-prioritize-vms-for-kubernetes-over-bare-metal>)

Author: Jack Wallen

Published: 2026-07-23T05:40:01Z

Content type: article

Language: en

Sources: [Platform Engineering Blog](<https://devfeed.tech/sources/platform-engineering-blog.md>)

Topics: [virtualization](<https://devfeed.tech/topics/virtualization.md>), [Kubernetes](<https://devfeed.tech/topics/kubernetes.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [Scalability](<https://devfeed.tech/topics/scalability.md>), [Security](<https://devfeed.tech/topics/security.md>), [Amazon Web Services](<https://devfeed.tech/topics/aws.md>), [Nitro System](<https://devfeed.tech/topics/nitro-system.md>), [Multi-tenancy](<https://devfeed.tech/topics/multi-tenancy.md>)

Tags: [aws](<https://devfeed.tech/tags/aws.md>), [containers](<https://devfeed.tech/tags/containers.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [multi-tenancy](<https://devfeed.tech/tags/multi-tenancy.md>), [nitro-system](<https://devfeed.tech/tags/nitro-system.md>), [scalability](<https://devfeed.tech/tags/scalability.md>), [security](<https://devfeed.tech/tags/security.md>), [virtual-machines](<https://devfeed.tech/tags/virtual-machines.md>), [virtualization](<https://devfeed.tech/tags/virtualization.md>)

### AI overview

Cloud providers generally run Kubernetes and other containerized workloads on virtual machines rather than bare metal because virtualization offers security, isolation, flexibility, scalability, and near-bare-metal performance. AWS Nitro and Firecracker help reduce virtualization overhead, while bare metal remains reserved for specialized performance or hardware-access requirements.

### Source excerpt

Why do cloud giants use VMs for Kubernetes? Learn why AWS, Azure, and Google prioritize Virtual Machines for containerized workloads over bare metal, focusing on security and scalability.

## How platform engineering plus VMs ease modernization

DevFeed: [How platform engineering plus VMs ease modernization](<https://devfeed.tech/articles/how-platform-engineering-plus-vms-ease-modernization-12165.md>)

Original publisher: [Read original article](<https://platformengineering.org/blog/how-platform-engineering-plus-vms-eases-modernization>)

Author: Jennifer Riggins

Published: 2026-07-23T05:40:01Z

Content type: article

Language: en

Sources: [Platform Engineering Blog](<https://devfeed.tech/sources/platform-engineering-blog.md>)

Topics: [Platform Engineering](<https://devfeed.tech/topics/platform-engineering.md>), [virtualization](<https://devfeed.tech/topics/virtualization.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [Cloud Native Ecosystem](<https://devfeed.tech/topics/cloud-native-ecosystem.md>), [Security](<https://devfeed.tech/topics/security.md>), [Scalability](<https://devfeed.tech/topics/scalability.md>), [Provisioning](<https://devfeed.tech/topics/provisioning.md>)

Tags: [architecture](<https://devfeed.tech/tags/architecture.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [cloud-native](<https://devfeed.tech/tags/cloud-native.md>), [containers](<https://devfeed.tech/tags/containers.md>), [engineering](<https://devfeed.tech/tags/engineering.md>), [idp](<https://devfeed.tech/tags/idp.md>), [infrastructure](<https://devfeed.tech/tags/infrastructure.md>), [operational](<https://devfeed.tech/tags/operational.md>), [platform](<https://devfeed.tech/tags/platform.md>), [platform-engineering](<https://devfeed.tech/tags/platform-engineering.md>), [policy](<https://devfeed.tech/tags/policy.md>), [provisioning](<https://devfeed.tech/tags/provisioning.md>), [scalability](<https://devfeed.tech/tags/scalability.md>), [security](<https://devfeed.tech/tags/security.md>), [virtual-machines](<https://devfeed.tech/tags/virtual-machines.md>)

### AI overview

The article explains how combining containers in virtual machines with platform engineering and internal developer platforms can ease modernization. It argues that VMs provide stronger isolation, security boundaries, resource flexibility, and performance comparable to bare metal, while a policy-driven platform layer improves provisioning, utilization, compliance, and scalability.

### Source excerpt

Explore why running containers in Virtual Machines (VMs) with a platform engineering strategy is essential for modern cloud environments. Learn how VMs deliver superior security, isolation, and resource management compared to bare metal, while achieving performance parity.

## Changing Interfaces Connected to netlab Links

DevFeed: [Changing Interfaces Connected to netlab Links](<https://devfeed.tech/articles/changing-interfaces-connected-to-netlab-links-11348.md>)

Original publisher: [Read original article](<https://blog.ipspace.net/2026/03/netlab-ifindex/>)

Published: 2026-03-30T05:27:00Z

Content type: tutorial

Language: en

Sources: [ipSpace.net blog](<https://devfeed.tech/sources/ipspace-net-blog.md>)

Topics: [networking](<https://devfeed.tech/topics/networking.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [virtual machines](<https://devfeed.tech/topics/virtual-machines.md>), [Cisco](<https://devfeed.tech/topics/cisco.md>)

Tags: [cisco](<https://devfeed.tech/tags/cisco.md>), [containers](<https://devfeed.tech/tags/containers.md>), [interfaces](<https://devfeed.tech/tags/interfaces.md>), [netlab](<https://devfeed.tech/tags/netlab.md>), [network](<https://devfeed.tech/tags/network.md>), [node](<https://devfeed.tech/tags/node.md>), [virtual-machines](<https://devfeed.tech/tags/virtual-machines.md>)

### AI overview

This article explains how netlab uses interface ifindex values to connect virtual lab interfaces to specific links. It examines how interface names and mappings behave across Ethernet devices, containers, KVM virtual machines, vrnetlab, and Linux processes running in containers.

### Source excerpt

Some netlab users want to accurately replicate their physical network's topology in a virtual lab. Ignoring the obvious caveats for a moment, the first hiccup is usually the interface naming. All bets are off if you're using anything but Ethernet in your actual network, but even if you did standardize on Ethernet, the container/VM interface names might not match the physical ones. netlab provided a solution for a long time - you can specify interface ifindex when attaching a node to a link. For example, use the following topology to connect Ethernet3 on R1 to Ethernet6 on R2: Read more ...

## BGP Labs: Goodbye, Cumulus Linux

DevFeed: [BGP Labs: Goodbye, Cumulus Linux](<https://devfeed.tech/articles/bgp-labs-goodbye-cumulus-linux-11341.md>)

Original publisher: [Read original article](<https://blog.ipspace.net/2026/03/bgp-labs-goodbye-cumulus/>)

Published: 2026-03-18T05:30:00Z

Content type: opinion

Language: en

Sources: [ipSpace.net blog](<https://devfeed.tech/sources/ipspace-net-blog.md>)

Topics: [BGP](<https://devfeed.tech/topics/bgp.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [Linux](<https://devfeed.tech/topics/linux.md>), [virtual machines](<https://devfeed.tech/topics/virtual-machines.md>)

Tags: [bgp](<https://devfeed.tech/tags/bgp.md>), [containers](<https://devfeed.tech/tags/containers.md>), [end-of-life](<https://devfeed.tech/tags/end-of-life.md>), [linux](<https://devfeed.tech/tags/linux.md>), [netlab](<https://devfeed.tech/tags/netlab.md>), [virtual-machines](<https://devfeed.tech/tags/virtual-machines.md>)

### AI overview

The author explains why the Online BGP Labs project moved away from Cumulus Linux. Problems included abandoned containers, crashes, a less suitable user interface after the NVIDIA acquisition, and discontinued or restricted Vagrant boxes. The author has now cleaned up more than 50 lab exercises, using FRRouting and Arista cEOS as alternatives.

### Source excerpt

When I started the Online BGP Labs project in mid-2023, Cumulus Linux still seemed like a good platform to use. You could run devices as virtual machines (we were still supporting VirtualBox) or in containers (containerlab was improving with every release), and it looked more polished than bare-bones FRRouting. Things only went downhill from there (from the perspective of offering a free and easy-to-use solution with a CLI resembling commonly-used devices): Read more ...

## Keeping it boring: the incident.io technology stack

DevFeed: [Keeping it boring: the incident.io technology stack](<https://devfeed.tech/articles/keeping-it-boring-the-incident-io-technology-stack-11862.md>)

Original publisher: [Read original article](<https://incident.io/blog/keeping-it-boring-the-incidentio-technology-stack>)

Author: Matthew Barrington

Published: 2026-02-26T15:28:47Z

Content type: article

Language: en

Sources: [The incident.io Blog](<https://devfeed.tech/sources/the-incident-io-blog.md>)

Topics: [Cloud](<https://devfeed.tech/topics/cloud.md>), [Kubernetes](<https://devfeed.tech/topics/kubernetes.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [Google](<https://devfeed.tech/topics/google.md>), [cloud-infrastructure](<https://devfeed.tech/topics/cloud-infrastructure.md>), [configuration](<https://devfeed.tech/topics/configuration.md>), [observability](<https://devfeed.tech/topics/observability.md>), [Processes](<https://devfeed.tech/topics/processes.md>)

Tags: [cloud](<https://devfeed.tech/tags/cloud.md>), [configuration](<https://devfeed.tech/tags/configuration.md>), [containers](<https://devfeed.tech/tags/containers.md>), [customers](<https://devfeed.tech/tags/customers.md>), [gcp](<https://devfeed.tech/tags/gcp.md>), [google-cloud](<https://devfeed.tech/tags/google-cloud.md>), [incident](<https://devfeed.tech/tags/incident.md>), [incident-channel](<https://devfeed.tech/tags/incident-channel.md>), [incident-management](<https://devfeed.tech/tags/incident-management.md>), [incident-response](<https://devfeed.tech/tags/incident-response.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [observability](<https://devfeed.tech/tags/observability.md>), [outage](<https://devfeed.tech/tags/outage.md>), [platform](<https://devfeed.tech/tags/platform.md>), [post-mortem](<https://devfeed.tech/tags/post-mortem.md>), [processes](<https://devfeed.tech/tags/processes.md>), [slack-incident](<https://devfeed.tech/tags/slack-incident.md>), [software](<https://devfeed.tech/tags/software.md>), [technology-stack](<https://devfeed.tech/tags/technology-stack.md>), [virtual-machines](<https://devfeed.tech/tags/virtual-machines.md>)

### AI overview

incident.io describes an intentionally simple technology stack built around managed Google Cloud services and a small platform team. Its default compute environment is GKE Autopilot, while workloads with long-lived processes or substantial storage or resource needs run on Google Compute Engine virtual machines. The article discusses the operational trade-offs of managed Kubernetes, including limitations around node lifetimes, system namespaces, and DNS configuration, and explains the use of Cloud Init for immutable, short-lived hosts.

### Source excerpt

This is the story of how incident.io keeps its technology stack intentionally boring, scaling to thousands of customers with a lean platform team by relying on managed GCP services and a small set of well-chosen tools.

## Safe Yolo Mode: Running LLM Agents in VMs with Libvirt and Virsh

DevFeed: [Safe Yolo Mode: Running LLM Agents in VMs with Libvirt and Virsh](<https://devfeed.tech/articles/safe-yolo-mode-running-llm-agents-in-vms-with-libvirt-and-virsh-31870.md>)

Original publisher: [Read original article](<https://www.metachris.dev/2026/02/safe-yolo-mode-running-llm-agents-in-vms-with-libvirt-and-virsh/>)

Author: Chris Hager

Published: 2026-02-10T00:00:00Z

Content type: tutorial

Language: en

Sources: [Chris Hager](<https://devfeed.tech/sources/chris-hager.md>)

Topics: [LLMs](<https://devfeed.tech/topics/llms.md>), [virtualization](<https://devfeed.tech/topics/virtualization.md>), [Security](<https://devfeed.tech/topics/security.md>), [Linux](<https://devfeed.tech/topics/linux.md>), [qemu](<https://devfeed.tech/topics/qemu.md>), [ssh](<https://devfeed.tech/topics/ssh.md>)

Tags: [linux](<https://devfeed.tech/tags/linux.md>), [llm-agents](<https://devfeed.tech/tags/llm-agents.md>), [llms](<https://devfeed.tech/tags/llms.md>), [security](<https://devfeed.tech/tags/security.md>), [tool-use](<https://devfeed.tech/tags/tool-use.md>), [virtual-machines](<https://devfeed.tech/tags/virtual-machines.md>)

### AI overview

A guide to isolating LLM agents in Linux virtual machines with libvirt and virsh. It explains how VM isolation can reduce risks from destructive operations and unauthorized access when agents receive broad tool-use permissions, and covers setup, cloud-image provisioning, VM creation, and SSH access.

### Source excerpt

This is a guide for isolating LLM agents in virtual machines, using libvirt and virsh on Linux servers. Running LLMs in VMs isolates them from the host system, mitigating numerous security risks such as destructive operations or unauthorized file access (i.e. private keys, secrets, credentials for communication tools). This is particularly important when granting LLM agents broad permissions, like auto-approving tool use ("yolo mode"). It's also useful to keep sessions running for extended periods of time, and to interact with agents from the phone / on the go.

## OCI Containers Come to Proxmox 9.1 - A First Look

DevFeed: [OCI Containers Come to Proxmox 9.1 - A First Look](<https://devfeed.tech/articles/oci-containers-come-to-proxmox-9-1-a-first-look-10643.md>)

Original publisher: [Read original article](<https://technotim.com/posts/proxmox-oci-images/>)

Author: Techno Tim

Published: 2025-11-20T13:00:00Z

Content type: article

Language: en

Sources: [Techno Tim](<https://devfeed.tech/sources/techno-tim.md>)

Topics: [Proxmox](<https://devfeed.tech/topics/proxmox.md>), [container images](<https://devfeed.tech/topics/container-images.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [hosting](<https://devfeed.tech/topics/hosting.md>)

Tags: [container-images](<https://devfeed.tech/tags/container-images.md>), [containers](<https://devfeed.tech/tags/containers.md>), [homelab](<https://devfeed.tech/tags/homelab.md>), [hosting](<https://devfeed.tech/tags/hosting.md>), [preview](<https://devfeed.tech/tags/preview.md>), [proxmox](<https://devfeed.tech/tags/proxmox.md>), [virtual-machines](<https://devfeed.tech/tags/virtual-machines.md>)

### AI overview

Proxmox 9.1 adds tech-preview support for OCI container images. The article explains how Proxmox pulls images from registries, stores them as templates, and runs them inside LXC wrappers with LXC-based networking and resource allocation. A Grafana image is shown launching successfully in this setup.

### Source excerpt

Proxmox 9.1 introduces support for OCI container images, bringing Docker-style workloads into the Proxmox ecosystem for the first time. It's still a tech preview, but it's a promising step toward more flexible application hosting inside Proxmox. Watch the video Why OCI Support Matters Until now, Proxmox has traditionally focused on virtual machines and LXC containers. Both are powerful, ...

## ansible-k3s-on-vms updated to Debian 13 (Trixie)

DevFeed: [ansible-k3s-on-vms updated to Debian 13 (Trixie)](<https://devfeed.tech/articles/ansible-k3s-on-vms-updated-to-debian-13-trixie-39538.md>)

Original publisher: [Read original article](<https://blog.wagemakers.be/blog/2025/11/13/ansible-k3s-trixie/>)

Author: Staf Wagemakers

Published: 2025-11-13T04:30:00Z

Content type: release

Language: en

Sources: [stafwag Blog](<https://devfeed.tech/sources/stafwag-blog.md>)

Topics: [Ansible](<https://devfeed.tech/topics/ansible.md>), [k3s](<https://devfeed.tech/topics/k3s.md>), [Debian](<https://devfeed.tech/topics/debian.md>), [Raspberry Pi](<https://devfeed.tech/topics/raspberry-pi.md>), [virtual machines](<https://devfeed.tech/topics/virtual-machines.md>), [Cloud](<https://devfeed.tech/topics/cloud.md>)

Tags: [ansible](<https://devfeed.tech/tags/ansible.md>), [changelog](<https://devfeed.tech/tags/changelog.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [cloudinit](<https://devfeed.tech/tags/cloudinit.md>), [cluster](<https://devfeed.tech/tags/cluster.md>), [debian](<https://devfeed.tech/tags/debian.md>), [debugging](<https://devfeed.tech/tags/debugging.md>), [k3s](<https://devfeed.tech/tags/k3s.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [linux](<https://devfeed.tech/tags/linux.md>), [pi](<https://devfeed.tech/tags/pi.md>), [pi-4](<https://devfeed.tech/tags/pi-4.md>), [release](<https://devfeed.tech/tags/release.md>), [virtual-machines](<https://devfeed.tech/tags/virtual-machines.md>)

### AI overview

The article announces updated Ansible roles for provisioning virtual machines and deploying k3s on a Raspberry Pi 4 cluster. The roles were updated for Debian 13 Trixie and include new templates, examples, and fixes across several roles.

### Source excerpt

I use the lightweight Kubernetes K3s on a 3-node Raspberry Pi 4 cluster. And created a few ansible roles to provision the virtual machines with cloud image with cloud-init and deploy k3s on it. I updated the roles below to be compatible with the latest Debian release: Debian 13 Trixie. With this release comes a new movie ;-)

## Solving virtual machine puzzles: How AI is optimizing cloud computing

DevFeed: [Solving virtual machine puzzles: How AI is optimizing cloud computing](<https://devfeed.tech/articles/solving-virtual-machine-puzzles-how-ai-is-optimizing-cloud-computing-6876.md>)

Original publisher: [Read original article](<https://research.google/blog/solving-virtual-machine-puzzles-how-ai-is-optimizing-cloud-computing/>)

Published: 2025-10-17T17:56:35Z

Content type: article

Language: en

Sources: [The latest research from Google](<https://devfeed.tech/sources/the-latest-research-from-google.md>)

Topics: [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [cloud-computing](<https://devfeed.tech/topics/cloud-computing.md>), [Algorithms & Theory](<https://devfeed.tech/topics/algorithms-theory.md>), [data centers](<https://devfeed.tech/topics/data-centers.md>), [servers](<https://devfeed.tech/topics/servers.md>), [Provisioning](<https://devfeed.tech/topics/provisioning.md>)

Tags: [2025](<https://devfeed.tech/tags/2025.md>), [ai](<https://devfeed.tech/tags/ai.md>), [algorithms](<https://devfeed.tech/tags/algorithms.md>), [algorithms-theory](<https://devfeed.tech/tags/algorithms-theory.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [cloud-computing](<https://devfeed.tech/tags/cloud-computing.md>), [distributed-systems-parallel-computing](<https://devfeed.tech/tags/distributed-systems-parallel-computing.md>), [efficiency](<https://devfeed.tech/tags/efficiency.md>), [google](<https://devfeed.tech/tags/google.md>), [packing](<https://devfeed.tech/tags/packing.md>), [provisioning](<https://devfeed.tech/tags/provisioning.md>), [research](<https://devfeed.tech/tags/research.md>), [resource](<https://devfeed.tech/tags/resource.md>), [scale](<https://devfeed.tech/tags/scale.md>), [server](<https://devfeed.tech/tags/server.md>), [servers](<https://devfeed.tech/tags/servers.md>), [software-systems-engineering](<https://devfeed.tech/tags/software-systems-engineering.md>), [virtual-machines](<https://devfeed.tech/tags/virtual-machines.md>)

### AI overview

Google Research presents LAVA, a scheduling system that uses AI models to continuously predict and adapt to virtual machine lifetimes. Its NILAS, LAVA, and LARS algorithms improve VM allocation and rescheduling in large cloud data centers, reducing stranded resources and improving server efficiency.

### Source excerpt

Algorithms & Theory

## Announcing per-sec billing, new Droplet plans, BYOIP, and NAT gateway to reduce scaling costs

DevFeed: [Announcing per-sec billing, new Droplet plans, BYOIP, and NAT gateway to reduce scaling costs](<https://devfeed.tech/articles/announcing-per-sec-billing-new-droplet-plans-byoip-and-nat-gateway-to-reduce-scaling-costs-19876.md>)

Original publisher: [Read original article](<https://www.digitalocean.com/blog/dropletplans-persecbilling-byoip-natgateway>)

Author: Nihar Namjoshi

Published: 2025-10-02T08:03:13Z

Content type: release

Language: en

Sources: [DigitalOcean](<https://devfeed.tech/sources/digitalocean.md>)

Topics: [Digital Ocean](<https://devfeed.tech/topics/digital-ocean.md>), [Cloud](<https://devfeed.tech/topics/cloud.md>), [cloud-infrastructure](<https://devfeed.tech/topics/cloud-infrastructure.md>), [virtual machines](<https://devfeed.tech/topics/virtual-machines.md>), [VPC](<https://devfeed.tech/topics/vpc.md>), [CI/CD](<https://devfeed.tech/topics/cicd.md>)

Tags: [ci-cd](<https://devfeed.tech/tags/ci-cd.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [cloud-infrastructure](<https://devfeed.tech/tags/cloud-infrastructure.md>), [digitalocean](<https://devfeed.tech/tags/digitalocean.md>), [droplets](<https://devfeed.tech/tags/droplets.md>), [network](<https://devfeed.tech/tags/network.md>), [product-updates](<https://devfeed.tech/tags/product-updates.md>), [virtual-machines](<https://devfeed.tech/tags/virtual-machines.md>), [vpc](<https://devfeed.tech/tags/vpc.md>)

### AI overview

DigitalOcean announces per-second billing for Droplets, new dedicated Droplet plans, generally available BYOIP, and a VPC NAT Gateway. The updates target more precise cost control, performance upgrades, IP reputation protection, and centralized egress management.

### Source excerpt

To help users cut down on cloud spending that's wasted due to over-provisioning and inflexible billing models, we're introducing tools that offer granular control without sacrificing simplicity or cost-effectiveness. We're excited to announce new product updates that offer granular cost control, improved performance, and a clear path to savings. TL;DR DigitalOcean has transitioned to per-second billing for Droplets. Starting from January 1, 2026, you only pay for the exact compute time you use, perfect for slashing costs on ephemeral tasks and CI/CD pipelines. Create Droplets for short-lived workloads. New dedicated Droplet plans are now generally available for a seamless performance upgrade. Visit your DigitalOcean console to create these new Droplets. Bring your own IP is now generally available to protect your IP reputation. Check out our documentation or visit your DigitalOcean console to bring your own ip. VPC NAT gateway is now generally available for centralized egress and static IPs. Join our webinar: Stop the manual struggle of managing NAT instances and bastion hosts or check out our documentation or visit your DigitalOcean console to set up your NAT gateway. Droplets per-second billing slashes costs for ephemeral workloads Traditional hourly billing models for virtual machines have resulted in customers paying for idle time, even for short-lived workloads. Starting from Jan 1, 2026, our billing model transitioned to a per-second basis for Droplets, with a minimum charge of 60 seconds or $0.01, whichever is higher. This new approach aims to optimize cost control by charging for exact usage over a minute, making it simple to get precise billing for your actual usage. For sustained workloads, the monthly cap of 672 hours (24 hours x 28 days) of usage remains in place, ensuring your bill never exceeds the predictable monthly price. Imagine your development team uses a CI/CD pipeline that uses $84/month CPU-Optimized Droplet to run automated tests taking 10 mi

## Arista EOS Hates a Routing Instance with No Interfaces

DevFeed: [Arista EOS Hates a Routing Instance with No Interfaces](<https://devfeed.tech/articles/arista-eos-hates-a-routing-instance-with-no-interfaces-11236.md>)

Original publisher: [Read original article](<https://blog.ipspace.net/2025/09/eos-no-interfaces/>)

Published: 2025-09-18T05:20:00Z

Content type: article

Language: en

Sources: [ipSpace.net blog](<https://devfeed.tech/sources/ipspace-net-blog.md>)

Topics: [BGP](<https://devfeed.tech/topics/bgp.md>), [bug](<https://devfeed.tech/topics/bug.md>), [debug](<https://devfeed.tech/topics/debug.md>), [Ansible](<https://devfeed.tech/topics/ansible.md>), [IP routing](<https://devfeed.tech/topics/ip-routing.md>), [Containers](<https://devfeed.tech/topics/containers.md>), [virtual machines](<https://devfeed.tech/topics/virtual-machines.md>)

Tags: [ansible](<https://devfeed.tech/tags/ansible.md>), [bgp](<https://devfeed.tech/tags/bgp.md>), [bug](<https://devfeed.tech/tags/bug.md>), [containers](<https://devfeed.tech/tags/containers.md>), [debug](<https://devfeed.tech/tags/debug.md>), [ip-routing](<https://devfeed.tech/tags/ip-routing.md>), [netlab](<https://devfeed.tech/tags/netlab.md>), [virtual-machines](<https://devfeed.tech/tags/virtual-machines.md>)

### AI overview

A debugging investigation finds that Arista EOS fails to configure BGP and enable IP routing when the default VRF has no interfaces. The issue occurs in container and virtual-machine deployments across multiple EOS releases, while the error message is misleading.

### Source excerpt

I always ask engineers reporting a netlab bug to provide a minimal lab topology that would reproduce the error, sometimes resulting in "interesting" side effects. For example, I was trying to debug a BGP-related Arista EOS issue using a netlab topology similar to this one: defaults.device: eos module: [ bgp ] nodes: a: { bgp.as: 65000 } b: { bgp.as: 65001 } Imagine my astonishment when the two switches failed to configure BGP. Here's the error message I got when running the netlab's deploy device configurations Ansible playbook: Read more ...

## QEMU version 10.1.0 released

DevFeed: [QEMU version 10.1.0 released](<https://devfeed.tech/articles/qemu-version-10-1-0-released-32653.md>)

Original publisher: [Read original article](<https://www.qemu.org/2025/08/26/qemu-10-1-0/>)

Published: 2025-08-26T23:25:00Z

Content type: release

Language: en

Sources: [QEMU](<https://devfeed.tech/sources/qemu.md>)

Topics: [qemu](<https://devfeed.tech/topics/qemu.md>), [version](<https://devfeed.tech/topics/version.md>), [virtualization](<https://devfeed.tech/topics/virtualization.md>), [virtual machines](<https://devfeed.tech/topics/virtual-machines.md>), [RISC-V](<https://devfeed.tech/topics/riscv.md>), [cpu](<https://devfeed.tech/topics/cpu.md>), [Kernel](<https://devfeed.tech/topics/kernel.md>), [Arm](<https://devfeed.tech/topics/arm.md>), [InfiniBand](<https://devfeed.tech/topics/infiniband.md>), [intel](<https://devfeed.tech/topics/intel.md>), [GB200](<https://devfeed.tech/topics/gb200.md>)

Tags: [arm](<https://devfeed.tech/tags/arm.md>), [cxl](<https://devfeed.tech/tags/cxl.md>), [gb200](<https://devfeed.tech/tags/gb200.md>), [intel](<https://devfeed.tech/tags/intel.md>), [ipv6](<https://devfeed.tech/tags/ipv6.md>), [kernel](<https://devfeed.tech/tags/kernel.md>), [kvm](<https://devfeed.tech/tags/kvm.md>), [migration](<https://devfeed.tech/tags/migration.md>), [qemu](<https://devfeed.tech/tags/qemu.md>), [qemu-10-1](<https://devfeed.tech/tags/qemu-10-1.md>), [rdma](<https://devfeed.tech/tags/rdma.md>), [release](<https://devfeed.tech/tags/release.md>), [releases](<https://devfeed.tech/tags/releases.md>), [risc-v](<https://devfeed.tech/tags/risc-v.md>), [version](<https://devfeed.tech/tags/version.md>), [virtual-machines](<https://devfeed.tech/tags/virtual-machines.md>), [virtualization](<https://devfeed.tech/tags/virtualization.md>), [x86](<https://devfeed.tech/tags/x86.md>)

### AI overview

QEMU 10.1.0 has been released with more than 2,700 commits from 226 authors. Highlights include confidential-guest support, live-migration improvements, Windows guest load querying, new ARM and RISC-V capabilities, and expanded KVM and x86 virtualization support.

### Source excerpt

We'd like to announce the availability of the QEMU 10.1.0 release. This release contains 2700+ commits from 226 authors.

## Network Digital Twins: Between PowerPoint and Reality

DevFeed: [Network Digital Twins: Between PowerPoint and Reality](<https://devfeed.tech/articles/network-digital-twins-between-powerpoint-and-reality-11196.md>)

Original publisher: [Read original article](<https://blog.ipspace.net/2025/06/digital-twins-powerpoint-reality/>)

Published: 2025-06-19T07:16:00Z

Content type: opinion

Language: en

Sources: [ipSpace.net blog](<https://devfeed.tech/sources/ipspace-net-blog.md>)

Topics: [Network](<https://devfeed.tech/topics/network.md>), [networking](<https://devfeed.tech/topics/networking.md>), [virtual machines](<https://devfeed.tech/topics/virtual-machines.md>), [virtualization](<https://devfeed.tech/topics/virtualization.md>), [Hardware](<https://devfeed.tech/topics/hardware.md>), [cpu](<https://devfeed.tech/topics/cpu.md>)

Tags: [automation](<https://devfeed.tech/tags/automation.md>), [cpu](<https://devfeed.tech/tags/cpu.md>), [examples](<https://devfeed.tech/tags/examples.md>), [hardware](<https://devfeed.tech/tags/hardware.md>), [network](<https://devfeed.tech/tags/network.md>), [networking](<https://devfeed.tech/tags/networking.md>), [virtual-machines](<https://devfeed.tech/tags/virtual-machines.md>), [virtualization](<https://devfeed.tech/tags/virtualization.md>)

### AI overview

The article discusses why networking digital twins have struggled to move beyond demonstrations. It identifies limitations involving supported interface technologies, interface-name mapping, chassis and line-card modeling, interface counts, resource requirements, clustered deployment, and the fidelity of virtual data-plane behavior.

### Source excerpt

A Network Artist left an interesting remark on one of my blog posts: It's kind of confusing sometimes to see the digital twin (being a really good idea) never really take off. His remark prompted me to resurface a two-year-old draft listing a bunch of minor annoyances that make Networking Digital Twins more of a PowerPoint project than a reality. Read more ...

## ArubaCX VXLAN Routing Packets Have Invalid Lengths

DevFeed: [ArubaCX VXLAN Routing Packets Have Invalid Lengths](<https://devfeed.tech/articles/arubacx-cannot-count-when-dealing-with-vxlan-11193.md>)

Original publisher: [Read original article](<https://blog.ipspace.net/2025/06/aruba-vxlan-packet-length/>)

Published: 2025-06-12T05:08:00Z

Content type: tutorial

Language: en

Sources: [ipSpace.net blog](<https://devfeed.tech/sources/ipspace-net-blog.md>)

Topics: [VXLAN](<https://devfeed.tech/topics/vxlan.md>), [networking](<https://devfeed.tech/topics/networking.md>), [Linux](<https://devfeed.tech/topics/linux.md>), [virtual machines](<https://devfeed.tech/topics/virtual-machines.md>)

Tags: [capture](<https://devfeed.tech/tags/capture.md>), [ethernet](<https://devfeed.tech/tags/ethernet.md>), [linux](<https://devfeed.tech/tags/linux.md>), [netlab](<https://devfeed.tech/tags/netlab.md>), [tailscale](<https://devfeed.tech/tags/tailscale.md>), [virtual-machines](<https://devfeed.tech/tags/virtual-machines.md>), [vxlan](<https://devfeed.tech/tags/vxlan.md>)

### AI overview

A netlab IRB test exposed that VXLAN packets generated by ArubaCX's routing process reported IP and UDP lengths four bytes larger than the actual packet. The article uses packet captures to trace the issue to a VLAN tag removed during software VXLAN encapsulation without a corresponding length adjustment.

### Source excerpt

This blog post describes yet another bizarre example of how reliable digital twins are, but don't worry; they all work great in PowerPoint. After "fixing" the integration tests to deal with ArubaCX's notion of VXLAN VNI having 16 bits, the bridging test worked, but the IRB tests kept failing. In the IRB test, the lab has two layer-3 switches. Each of them should be able to bridge within a VLAN/VXLAN segment and route across the segments. Read more ...

[Next page](<https://devfeed.tech/tags/virtual-machines.md?cursor=WyIyMDI1LTA2LTEyVDA1OjA4OjAwKzAwOjAwIiwgIjdhNzlmOTJlLWYyOTQtNGFjNC05NDRkLTk2YWU5OTA1NjUxOCJd>)