---
lastModified: 2026-10-09
---

# Environment

Each run gets a new Firecracker VM. Nothing is shared with other runs, and nothing is kept after the run.

## Sizes

| Size | vCPUs | Memory | Disk for `/workspace` |
|---|---|---|---|
| `s` | 1 | 2 GiB | 16 GiB |
| `m` | 2 | 4 GiB | 32 GiB |
| `l` | 4 | 8 GiB | 64 GiB |
| `xl` | 8 | 16 GiB | 128 GiB |

A VM sees its size's vCPUs. Each vCPU is a hardware thread, and it is not dedicated: VMs on a machine share its threads in proportion to vCPUs. A machine has 8 threads on 4 cores and runs VMs with at most 14 vCPUs in all. Each VM's disk is limited to 50 MB/s and 5,000 operations a second per vCPU, and its network to 25 MB/s per vCPU.

## The base

The base is the VM's root disk. Bases never change; a new base has a new name. `jinn bases` lists them.

`debian-12-20260801-0f9c2251`, the newest, is Debian 12 with: Python 3, git, curl, jq, ripgrep, xz, zstd, Chromium, OpenSSH client, and a 1440×900 Wayland display (sway, with Xwayland for X11 programs). The `screenshot` tool captures the display. From `bash`, `ydotool` types, clicks, drags and scrolls, `swaymsg` lists and moves windows, and `grim` and `wl-copy`/`wl-paste` take screenshots and use the clipboard. The older `debian-12-20260801-72c15f01` is the same with a plain background. Install anything else with [setup](/functions#bases-and-setup).

## Files

| Path | What it holds |
|---|---|
| `/workspace/in` | The input `.tar.gz`, unpacked. |
| `/workspace/out` | What the run returns. Everything here is delivered. |
| `/workspace` | The run's own disk, sized by the function's size. |

Setup and the agent's commands run as root.

## Network

The VM reaches the internet. It cannot reach:

- private addresses (`10.0.0.0/8`, `172.16.0.0/12`, `192.168.0.0/16`, `100.64.0.0/10`);
- link-local addresses, including cloud metadata services (`169.254.0.0/16`);
- other VMs, or the machine it runs on;
- mail servers on port 25.

New connections are limited to 200 a second.

## Credentials

- Your model key never enters the VM. The model is called from outside it.
- Custom tools are called from outside the VM. Their secrets never enter it.
- Secret environment variables do enter the VM, as variables.
- The VM has no cloud credentials.

## What is kept

The VM and its disks are destroyed when the run ends. Inputs, outputs and logs are stored encrypted with a Jinn KMS key, and deleted 30 days after the run, with the run's record. Functions, their versions and their secrets are kept while the account exists.
