Hacker News

Favorites Setup
Comment by okanat | original | Unikernels were hard. key word: were
[−]okanat · 2026-10-11 Sun 00:11 UTC · link
Are their abstraction boundaries protected by virtual memory and syscall interface such the submodules of a program cannot corrupt parts of memory that belong to others? Can I restart subtasks without affecting others? A traditional OS gives me all of that with relatively minimal overhead.

With a capability-based microkernel you get to assign ownership and resources to a very granular level that increases robustness against crashes and protection against attacks to the core system policy. A unikernel can give all of that but I feel like then it will be worse to program against rather than a microkernel.

So overall I don't see any advantage of unikernels. They don't help you write more correct programs IMO and the performance gains are limited.