A Jio microVM is a Linux virtual machine restored through KVM from a verified, prewarmed template. It is the isolation unit for one running session generation.
Restore path
verified template
-> private copy-on-write memory map
-> new KVM VM and fixed vCPUs
-> restored machine and device state
-> fresh identity, storage, and network configuration
-> guest readiness receipt
-> SSH-ready sessionThe immutable template memory is shared until a guest writes to a page. Each VM receives private writable memory, a unique VM identity, fresh entropy, and a session-owned workspace.
Resource profiles
| Size | vCPU | RAM |
|---|---|---|
| Small | 1 | 2 GiB |
| Medium | 2 | 4 GiB |
| Large | 4 | 8 GiB |
| X-Large | 8 | 16 GiB |
The client library models all four fixed profiles. The current CLI and hosted compatibility endpoint expose Small, Medium, and Large. Profiles are immutable for a running VM; there is no hot resize.
Readiness
Creation is complete only after the guest, system files, workspace storage, network, and SSH access path report ready. Raw fork or restore time is not the user-visible startup boundary.
A session can be returned as starting while asynchronous creation continues.
Poll the session instead of assuming that an accepted request is SSH-ready.
Isolation boundary
Jio treats the guest workload as hostile and the host as trusted. KVM separates guest execution from the host, but the host kernel, Jio runtime, template, and operator remain inside the trusted computing base.
Jio does not claim confidential computing, attestation, or operator-blind execution.