FTL presents a cloud OS that runs a userspace OS in each container

The website of FTL, a project that calls itself a new operating system for clouds, lays out a design in which the OS is a library. Each container runs a userspace OS: a shared library that implements most OS concepts, such as Linux processes, the virtual file system (VFS) and TCP/IP. Underneath sits the FTL kernel, which isolates the containers (the site calls them userspace OS instances) and provides a minimal interface for implementing Linux system calls in userspace, "just like a hypervisor". By the site's description, that interface rests on lightweight hardware-based isolation (user mode), so bare-metal machines are not needed.

The site contrasts this with Linux. In Linux, processes talk to a monolithic kernel that handles process management, fork/exec, memory, signals, TCP/IP, /proc, /dev and drivers. In FTL, Linux processes make system calls into the userspace OS inside their container, and only a small kernel layer (vCPU, memory, drivers and similar) sits below it.

FTL is described as compatible with Linux binaries. As an example, the site says the Rust-based HTTP server that serves the FTL website is a Linux application running on FTL. It adds that you can also run unikernel-like specialized applications without POSIX abstractions.

The pitch is a mix of two kernel families: FTL "combines the best of microkernels (flexible & secure) and monolithic kernels (performant & simple)". The stated goal is to make lightweight containers as secure as VMs and to unlock new OS-level abilities in applications, without sacrificing performance. The site also claims the FTL kernel isolates containers better than existing monolithic kernels.

The developer-facing argument is that a userspace OS is easier to work with. The site says it makes it easy to add features, debug and upgrade the OS safely, "as if writing applications", and that it lets you extend most Linux kernel features without kernel or eBPF programming. Its examples: adding printfs, applying security updates, and adding new features quickly and safely.

Key facts

  • Each container runs its own userspace OS, a shared library implementing most OS concepts such as Linux process, VFS and TCP/IP.
  • The FTL kernel provides a minimal interface to implement Linux system calls in userspace, like a hypervisor, using lightweight hardware-based isolation (user mode); bare-metal machines are not needed.
  • FTL is described as compatible with Linux binaries; the Rust-based HTTP server serving the FTL website is said to be a Linux application running on FTL.
  • The stated goal is containers as secure as VMs without sacrificing performance, combining microkernel flexibility and security with monolithic kernel performance and simplicity.
  • The site says the design lets you extend most Linux kernel features without kernel or eBPF programming, for example adding printfs and applying security updates.

Why it matters

Containers share a host kernel, which makes them light but, as the FTL site puts it, less isolated than VMs. FTL's stated goal is to close that gap: containers as secure as VMs, without sacrificing performance. Its route is to move most of the OS out of the kernel and into a per-container library, leaving a small kernel with a hypervisor-like interface. The site presents this as combining the best of microkernels (flexible and secure) and monolithic kernels (performant and simple).

Who it affects

The pitch is aimed at people who run workloads in cloud containers and at people who want to customise OS behaviour. The site says you can build your own OS as a library, run unikernel-like specialized applications without POSIX abstractions, and extend Linux kernel features without kernel or eBPF programming.

How to use it

The site says existing Linux binaries run on FTL, and offers its own Rust-based HTTP server as an example of a Linux application running on it. It also says you do not need bare-metal machines. Beyond a "Read more" link, the page gives no installation steps, download link or pricing.

How solid is it

The material is the project's own web page, so everything in it is a claim by the project. One concrete demonstration is cited: the site's own HTTP server is said to run on FTL. The page offers no benchmarks, no performance figures and no evidence or test for the claims that FTL isolates better than monolithic kernels or is as secure as VMs. It names no authors, company or maintainers, and gives no release date, version number or licence.

Risks and caveats

Security and performance are described as goals, not demonstrated results. The extent of Linux compatibility (which syscalls or binaries work) is not specified, nor are supported hardware, cloud platforms or architectures. The page does not say whether the project is open source or what its availability status is. Anyone considering FTL would need to check these points elsewhere.

“In FTL, OS is just a library.”

— FTL website (ftl-os.org)