Unikernels are back because the practical frictions that once made them difficult have been removed by modern tooling and large models. A unikernel bundles application code and the minimal OS into one image, eliminating userland, shells, and many attack vectors that let intruders pivot and exfiltrate. That operating-system-as-legacy-design-debt matters now: frequent kernel and userland patching fails to stop real risk (recent KVM compromises illustrate this), whereas a single-purpose unikernel reduces runtime surface area and forces attacks to be targeted at application source. Ring separation and other traditional objections are solvable today, and for high-assurance use cases formally verified kernels like seL4 remain the other option.
Practical gaps - missing libraries, storage, and drivers - are now trivial to close with AI-assisted porting, reproducible tests, and overlays; examples include porting Stripe clients and even mkfs.xfs byte-for-byte using agents. Cloud-shaped storage patterns (S3 plus NVMe cache) replace bulky local stacks. Nix machine tests and overlays simplify integration and supply-chain fixes. A worked example shows an OCaml-based unikernel fleet (SPACELEANS) implementing NTP, networking, logging, OpenAI/Anthropic clients, payments, PII-safe logs, and a Microsoft Orleans-style distributed actor runtime, proving a distributed unikernel OS is feasible in days rather than years. Languages like OCaml, Rust, and Haskell are well suited today, though compile-time costs remain an operational consideration.
Summary generated by AI from the linked article. hn.today is not affiliated with Hacker News or Y Combinator.