Simple application VMs (hypervisor-based sandbox) based on Nix package manager.
You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
dump_stack() 9142fe53c6
Remove donate
4 kuukautta sitten
.github Remove donate 4 kuukautta sitten
docs Updated installation instructions for NixOS 10 kuukautta sitten
dot-desktop-fuse Switch to buildGoModule 10 kuukautta sitten
nixos ooops, nixos cannot compute 10 kuukautta sitten
os Build appvm from ../default.nix 1 vuosi sitten
patches virt-viewer: use title as subtitle 1 vuosi sitten
.envrc [feat] added environment files 1 vuosi sitten
.gitignore Update .gitignore 1 vuosi sitten
LICENSE Add LICENSE 2 vuotta sitten
Makefile Support remove run with `nix run` 1 vuosi sitten
README.md Update screenshot 1 vuosi sitten
appvm.go fix: stat made qcow2 image creation return error every time 10 kuukautta sitten
base.nix.go Do not specify session explicitly 1 vuosi sitten
builtin.go Update builtin chromium appvm description 1 vuosi sitten
default.nix nixpkgs-able default.nix 10 kuukautta sitten
generate.go Avoid of changing current work directory 1 vuosi sitten
go.mod Switch to buildGoModule 10 kuukautta sitten
go.sum Switch to buildGoModule 10 kuukautta sitten
local.nix.template.go Do no enable anything in default local.nix 1 vuosi sitten
shell.nix [feat] added environment files 1 vuosi sitten
xml.go Add --network switch to select a networking model (#22) 1 vuosi sitten

README.md

Documentation Status Donate Donate

Nix application VMs: security through virtualization

Simple application VMs (hypervisor-based sandbox) based on Nix package manager.

Uses one read-only /nix directory for all appvms. So creating a new appvm (but not first) is just about one minute.

appvm screenshot

Installation

See related documentation.

Usage

Search for applications

$ appvm search chromium

Run application

$ appvm start chromium
$ # ... long wait for first time, because we need to collect a lot of packages

Synchronize remote repos for applications

$ appvm sync

You can customize local settings in ~/.config/appvm/nix/local.nix.

Default hotkey to release cursor: ctrl+alt.

Shared directory

$ ls appvm/chromium
foo.tar.gz
bar.tar.gz

Close VM

$ appvm stop chromium

Automatic ballooning

Add this command:

$ appvm autoballoon

to crontab like that:

$ crontab -l
* * * * * /home/user/dev/go/bin/appvm autoballoon