Early preview · Linux x86_64

Disposable computers.
Persistent work.

Spawn isolated KVM development computers from OCI environments. Your tools live in the machine, your source stays on its own disk, and session credentials disappear when the machine stops.

curl -fsSL https://spawnr-cli.dev/install.sh | sh

spawnr setupthenspawnr doctor

host — spawnr

$ spawnr clone \ ghcr.io/acme/rust-dev:v1 \ git@github.com:acme/project.git

pulling environment · creating disks · booting KVM

✓ project-1 is ready

$ spawnr open project-1

SPAWNR MACHINE / project-1

dev@project-1 ~/workspace/project $

KVM vsock OCI
Hardware-backedCloud Hypervisor + KVM
Daemonless OCINo Docker socket required
Host-owned identityPrivate keys stay on the host
Reproducible runtimeVersioned and digest-pinned

The storage model

Three domains. One clean boundary.

Environment, source, and credentials have different lifetimes. Spawnr keeps them physically separate.

01

Environment

The development computer

Packages, compilers, system configuration, and toolchains. Mutable while you work; publishable as an OCI image.

  • Independent ext4 disk
  • OCI pull and publish
  • Reproducible base
02

Workspace

Your persistent source

Repository checkout, build outputs, and project files live on a separate disk that is never part of a published environment.

  • Independent per machine
  • Persistent across restarts
  • Excluded from publish
03

Session

Ephemeral host identity

Sanitized Git identity, GitHub authentication, shell history, and SSH-agent access exist only in guest tmpfs.

  • Memory-backed tmpfs
  • Revoked on stop
  • Structurally unpublishable

The workflow

From registry to shell in one command.

Bring an existing development image or start from a standard OCI base. Spawnr materializes it into a real Linux filesystem, boots it with KVM, and connects your terminal over a private vsock transport.

Explore the command reference
  1. 1
    Clone

    Pull an OCI environment and clone your repository inside an isolated machine.

    spawnr clone
  2. 2
    Open

    Enter an interactive PTY as a normal development user with session capabilities.

    spawnr open
  3. 3
    Publish

    Capture environment changes as OCI layers without source or session secrets.

    spawnr publish

Host identity, guest capability

Your private keys stay home.

Spawnr forwards the ability to request SSH signatures over vsock; it never copies key material. Only selected Git identity, public known-host records, and session-scoped GitHub authentication cross the boundary.

Read the security model

Linux-first · open source

Build the machine. Keep the work.

Spawnr is an early project for developers who want stronger isolation without surrendering a familiar shell.