frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

AWS Adds support for nested virtualization

https://github.com/aws/aws-sdk-go-v2/commit/3dca5e45d5ad05460b93410087833cbaa624754e
50•sitole•1h ago

Comments

sitole•1h ago
Support for nested virtualization has been added to the main SDKs. In the us-west-2 region, you can already see the "Nested Virtualization" option and use it with the new M8id, C8id, and R8id instance types.

This is really big news for micro-VM sandbox solutions like E2B, which I work on.

blibble•1h ago
welcome AWS to 2018!
ssl-3•34m ago
Yep. It's pretty boring. I've been using it at home for years and years with libvirt on very not-special consumer hardware. I guess the AWS clown is finally catching up on this one little not-new-at-all thing.
otterley•4m ago
I was an Amazon EC2 Specialist SA in a prior role, so I know a little about this.

If EC2 were like your home server, you might be right. And an EC2 bare metal instance is the closest approximation to that. That option was never disabled and we had some customers who rolled their own nested VM implementations on it.

But EC2 is not like your home server. There are some nontrivial considerations and requirements to offer nested virtualization at cloud scale:

1. Ensuring virtualized networking (VPC) works with nested VMs as well as with the primary VM

2. Making sure the environment (VMM etc) is sufficiently hardened to meet AWS's security standards so that nesting doesn't pose unintended threats or weaken EC2's isolation properties

3. Ensuring performance meets customer standards

4. Building a rock-solid control plane around it all

It's not just a trivial matter of flipping a bit.

farklenotabot•47m ago
Sounds expensive for legacy apps
bagels•46m ago
"* *Feature*: Launching nested virtualization. This feature allows you to run nested VMs inside virtual (non-bare metal) EC2 instances."
ATechGuy•45m ago
Would love to see performance numbers with nested virtualization, particularly that of IO-bound workloads.
api•42m ago
What's the performance impact for nested virtualization in general? I'd think this would be adding multiple layers of MMU overhead.
dwattttt•26m ago
From memory, the virtualisation operations themselves aren't nested. The VM instructions interact with the external virtualisation hardware, so it's more of a cooperative situation, e.g. a guest can create & manage virtualisation structures that are run alongside it.

I don't know if this applies to the specific nested virtualisation AWS are providing though.

gerdesj•41m ago
Could someone explain why this is might be a big deal?

I remember playing with nested virty some years ago and deciding it is a backwards step except for PoC and the like. Given I haven't personally run out of virty gear, I never needed to do a PoC.

paulfurtado•24m ago
It is great for isolation. There are so many VM based containerization solutions at this point, like Kata Containers, gvisor, and Firecracker. With kata, your kubernetes pods run in isolated VMs. It also opens the door for live migration of apps between ec2 instances, making some kinds of maintenance easier when you have persistent workloads. Even if not for security, there are so many ways a workload can break a machine such that you need to reboot or replace (like detaching an ebs volume with a mounted xfs filesystem at the wrong moment).

The place I've probably wanted it the most though is in CI/CD systems: it's always been annoying to build and test system images in EC2 in a generic way.

It also allows for running other third party appliances unmodified in EC2.

But also, almost every other execution environment offers this: GCP, VMWare, KVM, etc, so it's frustrating that EC2 has only offered it on their bare metal instance types. When ec2 was using xen 10+ years ago, it made sense, but they've been on kvm since the inception of nitro.

UltraSane•22m ago
You can now run VMs inside a cheaper AWS instance instead of having to pay for an entire bare-metal instance. This is useful for things like network simulation where you use QEMU to emulate network hardware.
anurag•37m ago
This is a big deal because you can now run Firecracker/other microVMs in an AWS VM instead of expensive AWS bare-metal instances.

GCP has had nested virtualization for a while.

parhamn•27m ago
whats the ~ perf hit of something like this?
largbae•18m ago
Nowadays nested just wastes the extra operating system overhead and I/O performance if your VM doesn't have paravirtualization drivers installed. CPUs all have hardware support.
otterley•2m ago
As a practical matter, anywhere from 5-15%.
iJohnDoe•15m ago
Was hoping this comment would be here. Firecracker and microVMs is a good use-case. Also, being able to simply test and develop is a nice to have.

Nested virtualization can mean a lot of things. Not just full VMs.

dangoodmanUT•25m ago
hell yes, finally

Show HN: FlareBar – Access your Cloudflare dashbord from macOS menu

https://flarebar.app/
1•mrbutttons•2m ago•0 comments

Rewriting an Objective-C project in Swift with the Xcode agent support

https://mastodon.social/@stroughtonsmith/116018205506714527
1•Austin_Conlon•3m ago•0 comments

Apple Confirms Revamped Siri Is Still Coming in 2026

https://www.macrumors.com/2026/02/12/siri-ios-26-launch-confirmed-apple/
1•newman314•4m ago•0 comments

ARC-AGI-1 and 2 LEADERBOARD

https://arcprize.org/leaderboard
1•doener•8m ago•1 comments

Show HN: Paragliding RL

https://southriverai.github.io/southriverblog/post.html?slug=the-speed-to-fly-in-2026
1•kozzion•9m ago•0 comments

Trump Justice Department Poised to Preserve Ticketmaster Monopoly

https://prospect.org/2026/02/12/trump-justice-department-ticketmaster-live-nation-monopoly/
1•leotravis10•10m ago•0 comments

Justice Department antitrust chief Gail Slater resigns

https://www.axios.com/2026/02/12/justice-antitrust-chief-gail-slater-resigns
1•leotravis10•11m ago•0 comments

Google may be cracking down on self-promotional 'best of' listicles

https://searchengineland.com/google-cracking-down-self-promotional-best-of-listicles-468227
1•gnabgib•14m ago•0 comments

Show HN: Sovereign Suite – A Recursive Logic Framework for AI Governance

https://github.com/holland202/Sovereign-Suite-Manifest
1•badatchess•18m ago•0 comments

Show HN: New Open Source Agent with 62 Stars on GitHub

https://github.com/dakotalock/holygrailopensource
2•Moriarty2027•22m ago•0 comments

Mitchell Hashimoto Launches 'Vouch' to Fight AI Slop in Open Source Ecosystem

https://itsfoss.com/news/mitchell-hashimoto-vouch/
2•WaitWaitWha•22m ago•1 comments

Ethnic minorities are driving America's startup boom

https://www.economist.com/finance-and-economics/2026/02/12/ethnic-minorities-are-driving-americas...
1•andsoitis•23m ago•0 comments

Authoring, simulating, and testing dynamic human-AI group conversations

https://research.google/blog/beyond-one-on-one-authoring-simulating-and-testing-dynamic-human-ai-...
1•gmays•24m ago•0 comments

PostgreSQL v19: Password expiration warnings

https://hexacluster.ai/blog/postgresql-v19-password-expiration-warnings
1•avivallssa•28m ago•0 comments

Show HN: Khaos – Every AI agent I tested broke in under 30 seconds

1•exordex•29m ago•0 comments

How Are Amps Modeled? [video]

https://www.youtube.com/watch?v=9YL8pwF7Mnc
2•dsego•32m ago•0 comments

What 1.4M emails reveal about America's most notorious sex offender

https://www.economist.com/interactive/international/2026/02/12/inside-epsteins-network
2•doener•33m ago•0 comments

Simile: The Simulation Company

https://twitter.com/joon_s_pk/status/2022023097017421874
1•jaehong747•35m ago•0 comments

Elide is an all-in-one, AI-native, open source software runtime

https://elide.dev/
2•shirian•37m ago•0 comments

The March Cliff: Why the 2026 Economic Collapse Is Different

https://ramakanth-d.medium.com/the-march-cliff-why-the-2026-economic-collapse-is-different-e1c619...
1•playhard•38m ago•2 comments

Welcome to the Great Regression

https://www.bloomberg.com/opinion/newsletters/2026-02-12/the-us-risks-a-great-regression
1•petethomas•39m ago•0 comments

Judge rules that LLM provided legal advice is open to discovery [pdf]

https://storage.courtlistener.com/recap/gov.uscourts.nysd.652138/gov.uscourts.nysd.652138.22.0.pdf
3•stingrae•40m ago•0 comments

My hot take on vibe coding for PMs

https://www.ddmckinnon.com/2026/02/11/my-%f0%9f%8c%b6-take-on-vibe-coding-for-pms/
1•awaxman11•43m ago•0 comments

AI: Brainrot Inducer or Cognitive Multiplier?

https://www.cjroth.com/blog/2026-02-12-brainrot
1•thoughtfulchris•44m ago•0 comments

Deft – a class and interface system for Clojure[video]

https://www.youtube.com/watch?v=dlW6YzwUZ-M
1•sammy0910•44m ago•0 comments

AI and consciousness: from objective descriptions to 'level zero'

https://randomseed.io/txt/ai-and-consciousness/
1•siefca•46m ago•1 comments

Cloudflare adds real-time Markdown rendering for AI agents

https://blog.cloudflare.com/markdown-for-agents/
5•thestackfox•47m ago•2 comments

A Read-Only Philosophical Archive on Restraint and AI Ethics

https://coexilia.io/coexilian-documents/
1•aegissolis•48m ago•1 comments

RFK Jr. food pyramid site links to Grok, which says you shouldn't trust RFK Jr

https://arstechnica.com/health/2026/02/rfk-jr-food-pyramid-site-links-to-grok-which-says-you-shou...
3•doener•48m ago•2 comments

Skip the Tips: A game to select "No Tip" but dark patterns try to stop you

https://skipthe.tips/
10•randycupertino•48m ago•4 comments