binaryRequired
string
Absolute host path of the firecracker executable.
kernelRequired
string
Absolute host path of the guest kernel image.
rootfsRequired
string
Absolute host path of the guest root filesystem image; each VM boots from a private copy.
tapRequired
string
Existing host TAP device for the guest network, at most 15 letters, digits, dots, hyphens or underscores. A provider owns it, so it runs one VM at a time.
guestMacRequired
string
MAC address of the guest network interface, as six hexadecimal pairs.
bootArgsRequired
string
Kernel boot arguments supplied to Firecracker.
sshRequired
{ readonly host: string; readonly user: string; readonly identity: string; readonly knownHosts: string; readonly port?: number; readonly binary?: string; }
How Outpost reaches the guest: host, user, identity file, trusted known_hosts file, optional port (default 22) and ssh binary.
rootOptional
string | undefined
Repository directory in the guest, default /workspace.
homeRequired
string
Agent home in the guest; it must match the guest user’s HOME or the boot check never succeeds.
cpusOptional
number | undefined
Guest vCPUs, default 2. It does not cap host CPU; jailer.cpuQuotaUs does.
memoryMbOptional
number | undefined
Guest memory in MiB, default 2048; jailer.memoryMaxMb must exceed it.
bootDeadlineMsOptional
number | undefined
Time allowed for the guest to answer over SSH with its prerequisites, default 60000. Past it acquisition fails with code timeout and the VM stops.
variablesOptional
Readonly<Record<string, string>> | undefined
Environment variables set for every command in the sandbox, as literal values. A key the agent also declares fails with code configuration.
jailerOptional
{ readonly binary: string; readonly directory: string; readonly cgroup: string; readonly uid: number; readonly gid: number; readonly cpuQuotaUs: number; readonly memoryMaxMb: number; readonly processes: number; } | undefined
Launch through the Firecracker jailer: root-owned binary and paths, a dedicated cgroup v2 parent with cpu, memory and pids controllers enabled, non-root uid and gid, cpuQuotaUs per 100000 microseconds (at least 1000), memoryMaxMb above guest memory and processes (at least 16). Outpost must already run as root and never calls sudo; without jailer, Firecracker runs as the calling user.