Environment
Updated 2026-10-09
Each run gets a new Firecracker VM. Nothing is shared with other runs, and nothing is kept after the run.
Sizes
| Size | vCPUs | Memory | Disk for /workspace |
|---|---|---|---|
s | 1 | 2 GiB | 16 GiB |
m | 2 | 4 GiB | 32 GiB |
l | 4 | 8 GiB | 64 GiB |
xl | 8 | 16 GiB | 128 GiB |
A VM sees its size's vCPUs. Each vCPU is a hardware thread, and it is not dedicated: VMs on a machine share its threads in proportion to vCPUs. A machine has 8 threads on 4 cores and runs VMs with at most 14 vCPUs in all. Each VM's disk is limited to 50 MB/s and 5,000 operations a second per vCPU, and its network to 25 MB/s per vCPU.
The base
The base is the VM's root disk. Bases never change; a new base has a new name. jinn bases lists them.
debian-12-20260801-0f9c2251, the newest, is Debian 12 with: Python 3, git, curl, jq, ripgrep, xz, zstd, Chromium, OpenSSH client, and a 1440×900 Wayland display (sway, with Xwayland for X11 programs). The screenshot tool captures the display. From bash, ydotool types, clicks, drags and scrolls, swaymsg lists and moves windows, and grim and wl-copy/wl-paste take screenshots and use the clipboard. The older debian-12-20260801-72c15f01 is the same with a plain background. Install anything else with setup.
Files
| Path | What it holds |
|---|---|
/workspace/in | The input .tar.gz, unpacked. |
/workspace/out | What the run returns. Everything here is delivered. |
/workspace | The run's own disk, sized by the function's size. |
Setup and the agent's commands run as root.
Network
The VM reaches the internet. It cannot reach:
- private addresses (
10.0.0.0/8,172.16.0.0/12,192.168.0.0/16,100.64.0.0/10); - link-local addresses, including cloud metadata services (
169.254.0.0/16); - other VMs, or the machine it runs on;
- mail servers on port 25.
New connections are limited to 200 a second.
Credentials
- Your model key never enters the VM. The model is called from outside it.
- Custom tools are called from outside the VM. Their secrets never enter it.
- Secret environment variables do enter the VM, as variables.
- The VM has no cloud credentials.
What is kept
The VM and its disks are destroyed when the run ends. Inputs, outputs and logs are stored encrypted with a Jinn KMS key, and deleted 30 days after the run, with the run's record. Functions, their versions and their secrets are kept while the account exists.