Reusable AWS CDK (Python) construct for provisioning AWS Lambda MicroVM images and launchers.
Project description
AWS Lambda MicroVM CDK Construct (Python)
A reusable AWS CDK v2 construct (pure Python, 3.11+) for provisioning AWS Lambda MicroVMs — Firecracker-based, VM-isolated, snapshot-fast serverless compute for AI sandboxes, interactive dev environments, and multi-tenant CI. Secure defaults, every AWS knob overridable, plus an escape hatch.
📜 Documentation | Blogs website
Contact details | mailto:ran.isenberg@ranthebuilder.cloud
Status: early development (targets a preview AWS API). Repo:
lambda-microvm-cdk-python· PyPI:lambda-microvm-cdk.
What it does
LambdaMicroVM is a typed wrapper around the L1 AWS::Lambda::MicrovmImage resource. In one
construct it zips your Dockerfile+app, uploads it to S3, creates least-privilege build and
VM-execution roles, resolves the managed base-image version, and emits a snapshotted MicroVM
image — with secure defaults and an overrides escape hatch for anything not yet modeled.
Running a MicroVM (run / suspend / resume / terminate) is a runtime API call, not CloudFormation — so it's driven with boto3 from your app or the E2E fixture, using the construct's typed properties (image ARN, execution role, connector ARNs, log group). There is no launcher Lambda / API Gateway / WAF — you call the runtime API directly.
Two planes
flowchart LR
subgraph CFN["Declarative — CloudFormation (this construct)"]
IMG["AWS::Lambda::MicrovmImage<br/>(LambdaMicroVM)"]
NC["AWS::Lambda::NetworkConnector<br/>(VPC egress — MicrovmNetworkConnector)"]
end
subgraph RT["Runtime API — boto3 (your app / E2E fixture)"]
RUN["RunMicrovm · Suspend · Resume · Terminate<br/>CreateMicrovmAuthToken"]
end
IMG -- "image ARN + exec role<br/>+ connector ARNs (props)" --> RUN
Images and connectors are declarative CDK; the running instance is runtime-only, wired from the construct's outputs.
Quickstart
Install
Add the package to your CDK app (Python 3.11+). aws-cdk-lib, constructs, and the
aws-cdk-aws-ec2-alpha module (used by the VPC-egress construct) are pulled in as dependencies.
pip install lambda-microvm-cdk
# or
uv add lambda-microvm-cdk
# or
poetry add lambda-microvm-cdk
Use
from aws_cdk import Stack
from lambda_microvm_cdk import LambdaMicroVM
class MyStack(Stack):
def __init__(self, scope, id, **kw):
super().__init__(scope, id, **kw)
vm = LambdaMicroVM(self, "Agent",
source="microvm_app", # dir with a Dockerfile (also: .zip path or s3_assets.Asset)
description="headless agent VM",
memory_mib=2048, # tier: 512|1024|2048|4096|8192
environment={"LOG_LEVEL": "info"}, # NEVER secrets — baked into the snapshot
# architecture defaults to ARM_64 (only value the service accepts today)
# enable_logging=True, os_capabilities=[], overrides={} ...
)
vm.image_arn # Fn::GetAtt ImageArn (token)
vm.execution_role # least-priv VM execution role (add workload perms on top)
vm.grant_run(caller) # attach least-priv RunMicrovm* to a runtime-caller principal
Custom VPC egress (optional)
Route the VM's outbound traffic through your VPC with MicrovmNetworkConnector. It's BYO-VPC —
you own the VPC (and whether it has internet egress). Pass the connector straight to
egress_connectors=[...]; the security group's rules are the egress policy (deny-all by default).
flowchart LR
vm["MicroVM<br/>image build + runtime"]
subgraph vpc["Your VPC — BYO · REJECT flow logs"]
direction TB
subgraph priv["Private subnets · PRIVATE_WITH_EGRESS"]
eni["Connector ENIs<br/>SG = egress policy:<br/>deny-all + allow tcp/443"]
end
subgraph pub["Public subnets"]
nat["NAT Gateway + EIP"]
end
igw["Internet Gateway"]
end
net(("Internet<br/>public.ecr.aws · PyPI · Bedrock"))
vm -->|"outbound via connector"| eni
eni -->|"0.0.0.0/0 → NAT"| nat
nat -->|"0.0.0.0/0 → IGW"| igw
igw <--> net
The security group is the only egress gate (deny-all + explicit allows, stateful); the NAT gateway has no rules — it just gives the private subnets a path to the internet. Full architecture + fully-private (no-NAT) option: Custom Egress docs.
Build-time vs run-time egress.
egress_connectorsis the image build's egress — the build runs yourDockerfilein a MicroVM, so the VPC must reach your base image + package repos (a NAT gateway, or private mirrors). A locked-down VPC with no route to those fails the build. For VPC egress only at runtime, leaveegress_connectorsempty and pass the connector torun_microvminstead.
import aws_cdk.aws_ec2 as ec2
from lambda_microvm_cdk import LambdaMicroVM, MicrovmNetworkConnector
# BYO VPC with a NAT gateway so the image build can reach public.ecr.aws + PyPI.
vpc = ec2.Vpc(self, "Vpc", max_azs=2, nat_gateways=1) # or an aws_ec2_alpha.VpcV2 — see sample/
connector = MicrovmNetworkConnector(
self,
"Egress",
vpc=vpc, # deny-all egress SG by default
)
connector.security_group.add_egress_rule(
ec2.Peer.any_ipv4(),
ec2.Port.tcp(443),
"HTTPS egress",
)
vm = LambdaMicroVM(
self,
"Agent",
source="microvm_app",
egress_connectors=[connector], # accepts the connector object or a raw ARN string
)
See sample/sample_stack.py for a full VpcV2 + NAT-gateway example.
Build & run flow
sequenceDiagram
participant Dev
participant CDK as CDK / CloudFormation
participant Svc as Lambda MicroVM service
participant App as your app / E2E fixture (boto3)
Dev->>CDK: cdk deploy (LambdaMicroVM)
CDK->>Svc: create MicrovmImage (S3 artifact + base image)
Svc-->>CDK: image CREATING -> CREATED (snapshot)
App->>Svc: RunMicrovm(imageArn, executionRoleArn, connectors, maxDuration)
Svc-->>App: microvmId, endpoint (PENDING -> RUNNING)
App->>Svc: CreateMicrovmAuthToken(allowedPorts=[{port:8080}])
App->>App: HTTPS request (X-aws-proxy-auth) -> assert
App->>Svc: TerminateMicrovm (guaranteed in teardown)
Sample app
sample/ is a deployable CDK app whose MicroVM runs a model worker on Amazon Bedrock
(us-east-1) — Amazon Nova 2 Lite by default (boto3 Converse), with Claude Opus 4.8 opt-in
(MODEL_PROVIDER=anthropic). The worker is tiered so the deterministic gate never depends on the model.
The E2E suite runs two tests against one VM:
echo— deterministic, no model. The E2E gate.bedrock— one model call (Nova default / Opus opt-in); the E2E test asks the model to sum two random numbers and asserts the reply contains the sum.agent— Claude Code headless (opt-in enhancement, not exercised by the E2E tests).
Local development
For working on the construct itself (not just consuming it). Uses uv,
ruff, and the AWS CDK CLI via npx (see the Makefile).
make dev # uv sync (venv + dev deps)
make lint # ruff format --check + ruff check + mypy
make unit # unit tests (no AWS; boto3 mocked)
make synth # npx aws-cdk synth the sample app (runs cdk-nag)
CI/CD and the docs pipeline are described in docs/pipeline.md.
Code contributions
Contributions are welcome — please open an issue or PR. PR titles follow the
feature | fix | docs | chore convention (validated in CI).
Connect
- Website: www.ranthebuilder.cloud
- Blog: ranthebuilder.cloud/blog
- X (Twitter): @RanBuilder
- Email: ran.isenberg@ranthebuilder.cloud
License
This library is licensed under the MIT-0 License. See the LICENSE file.
Project details
Release history Release notifications | RSS feed
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file lambda_microvm_cdk-0.1.0.tar.gz.
File metadata
- Download URL: lambda_microvm_cdk-0.1.0.tar.gz
- Upload date:
- Size: 2.0 MB
- Tags: Source
- Uploaded using Trusted Publishing? Yes
- Uploaded via: twine/6.1.0 CPython/3.13.13
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
dcc9b9e4470a2f9d918b18b7b62de52a4585492c040f5059eaf2fbab2bb6a506
|
|
| MD5 |
6edbd5e4e9bf4163129f2c1213061828
|
|
| BLAKE2b-256 |
4c8ed932bc7a6000450afc114180c3f7e8eeb613f813437497a1762360d223e8
|
Provenance
The following attestation bundles were made for lambda_microvm_cdk-0.1.0.tar.gz:
Publisher:
release.yml on ran-isenberg/lambda-microvm-cdk-python
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
lambda_microvm_cdk-0.1.0.tar.gz -
Subject digest:
dcc9b9e4470a2f9d918b18b7b62de52a4585492c040f5059eaf2fbab2bb6a506 - Sigstore transparency entry: 2167109466
- Sigstore integration time:
-
Permalink:
ran-isenberg/lambda-microvm-cdk-python@960ec09eaaad839b41679cc86610c0b5dda4157d -
Branch / Tag:
refs/tags/v0.1.0 - Owner: https://github.com/ran-isenberg
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
release.yml@960ec09eaaad839b41679cc86610c0b5dda4157d -
Trigger Event:
push
-
Statement type:
File details
Details for the file lambda_microvm_cdk-0.1.0-py3-none-any.whl.
File metadata
- Download URL: lambda_microvm_cdk-0.1.0-py3-none-any.whl
- Upload date:
- Size: 20.9 kB
- Tags: Python 3
- Uploaded using Trusted Publishing? Yes
- Uploaded via: twine/6.1.0 CPython/3.13.13
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
7621a3642facd786038a36eb3229bac898e8205d612afc2d7a67e7611ad985ab
|
|
| MD5 |
a2021955d1325ae9afad6e49c781175c
|
|
| BLAKE2b-256 |
b99b0a2002912681aae139b327baa9437c4eb2796619088f84c891a77f998834
|
Provenance
The following attestation bundles were made for lambda_microvm_cdk-0.1.0-py3-none-any.whl:
Publisher:
release.yml on ran-isenberg/lambda-microvm-cdk-python
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
lambda_microvm_cdk-0.1.0-py3-none-any.whl -
Subject digest:
7621a3642facd786038a36eb3229bac898e8205d612afc2d7a67e7611ad985ab - Sigstore transparency entry: 2167109479
- Sigstore integration time:
-
Permalink:
ran-isenberg/lambda-microvm-cdk-python@960ec09eaaad839b41679cc86610c0b5dda4157d -
Branch / Tag:
refs/tags/v0.1.0 - Owner: https://github.com/ran-isenberg
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
release.yml@960ec09eaaad839b41679cc86610c0b5dda4157d -
Trigger Event:
push
-
Statement type: