FTL: Cloud OS Runs Linux Containers in Userspace

Original: FTL: A new operating system for clouds

Why This Matters

Userspace OS design could lower the security gap between containers and VMs.

FTL is a new open-source OS for cloud environments that moves OS logic—processes, VFS, TCP/IP—into userspace libraries per container, using a minimal kernel with hypervisor-style hardware isolation, while staying compatible with existing Linux binaries.

FTL positions itself as a hybrid between microkernels and monolithic kernels. Each container runs its own userspace OS—a shared library implementing Linux abstractions like processes, VFS, and TCP/IP—while the FTL kernel exposes only a thin interface: vCPU scheduling, memory management, and drivers. The isolation model uses CPU user-mode hardware boundaries, similar to a hypervisor, without requiring bare-metal machines.

The pitch is container-level weight with VM-level security. Because OS logic lives in userspace, developers can patch, debug, or extend kernel features—adding print statements or security fixes—without touching kernel code or writing eBPF. The project also supports unikernel-style deployments that bypass POSIX entirely.

The roadmap is aggressive: v0.0.1 already runs a Rust HTTP server (which serves the project's own website), and v0.1.0 adds async Rust support with epoll and threading. Filesystem support is planned for November 2026, followed by Node.js/Go, SMP, container images, and 64-bit Arm by early 2027.

FTL is available on GitHub and is still in early-stage development.

Source

ftl-os.org — Read original →