mvm — Python SDK
Declare a microVM workload in Python. Write a function, decorate it, and the
mvmctl toolchain bakes it into a Nix-built Firecracker / libkrun microVM
image and boots it — no Dockerfile, no SSH, no agent code in your app.
pip install mvm
mvmctl (the Rust host CLI) is distributed separately and does the building,
booting, and signing. This package is the authoring surface it reads.
Quick start
# app.py
import mvm as mv
@mv.func(name="adder")
def add(a: int, b: int) -> int:
return a + b
mvmctl compile app.py # parse the script (no execution) → flake.nix + launch plan
mvmctl up --flake . # build the image and boot the microVM
@mv.func is the one-liner: it declares the workload, the app, and a function
entrypoint with sane defaults (nix_packages(["python312"]), 1 vCPU / 256 MB /
512 MB rootfs). For full control, declare the pieces explicitly:
import mvm as mv
mv.workload(id="hello")
@mv.app(
name="hello",
source=mv.local_path("."),
image=mv.nix_packages(["python312"]),
resources=mv.resources(cpu_cores=1, memory_mb=256, rootfs_size_mb=512),
env={"API_KEY": mv.secret("api-key")},
before_start=mv.hook("export TZ=UTC"),
after_start=mv.hook(["curl", "-fsS", "http://localhost:8080/health"]),
)
def main(name: str) -> str:
return f"hello {name}"
How it builds
mvmctl compile reads your file statically — the decorator and the
import mvm line are parsed as data, never executed, so nothing in your module
runs on the host. At image-build time the decorator and the import mvm line
are stripped from the bundled source, so the guest runs your plain function
with no SDK dependency inside the microVM.
You can also emit the canonical Workload IR in-process, for inspection or tests:
import mvm as mv
print(mv.emit_json()) # the IR mvmctl would produce
Lifecycle hooks
Four hook points, each a shell string or an argv list (or a list of them). Addons contribute their own hooks, merged at compile time:
| Hook | Runs |
|---|---|
before_build |
in the builder VM, before the image is assembled |
before_start |
in the guest, before the entrypoint |
after_start |
in the guest, after the entrypoint is up |
before_stop |
in the guest, on shutdown |
Building blocks
| Helper | Purpose |
|---|---|
mv.nix_packages([...]), mv.python_image(...), mv.node_image(...) |
base image |
mv.resources(cpu_cores=, memory_mb=, rootfs_size_mb=) |
per-VM budget |
mv.network(...), mv.egress(...) |
egress policy (default-deny) |
mv.python_deps(...), mv.node_deps(...) |
dependencies, installed into a sealed, audited volume |
mv.secret("name"), mv.literal("v") |
env values — secrets resolve on the host, never baked into the image |
Dev-only runtime
f.remote(...) / mv.session(...) call into a running function-VM, and
mv.Sandbox wraps local sandbox primitives. These are development
conveniences for build-time emission and introspection. Production microVMs are
observed through mvmctl output streams — there are no host-side .remote()
calls on the prod path.
Optional extras
pip install 'mvm[schema]' # pydantic-based schema derivation from type hints
Versioning
The SDK version tracks the mvmctl toolchain version: a workload emitted by
mvm X.Y.Z is consumed by mvmctl X.Y.Z. Install matching versions.
Links
- Source & issues: https://github.com/tinylabscom/mvm
- TypeScript SDK:
@runmvm/mvm
License
Apache-2.0 — see LICENSE.
Metadata
Release files for mvm 0.15.1
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| mvm-0.15.1.tar.gz | 48.8 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| mvm-0.15.1-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 102.3 kB
Release files / mvm-0.15.1.tar.gz
| Download URL | mvm-0.15.1.tar.gz |
|---|---|
| Size | 48.8 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
bb6a1dac03afb44db1b468300e901a0702d76aece3595328125862d4ec27b25e
|
|
BLAKE2b-256 checksum How to use checksums |
b44dc464d24f69319a24d5026a03af81da59042406834d02c6675e1702ccc011
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.12
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Jun 3, 2026.
Transparency logRelease files / mvm-0.15.1-py3-none-any.whl
| Download URL | mvm-0.15.1-py3-none-any.whl |
|---|---|
| Size | 53.5 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
be242e6f06cfcb80f558869171afa2ae091477ad544ea9e58baeb494ac126fc7
|
|
BLAKE2b-256 checksum How to use checksums |
053b2247cab6b0d6f3cd6b5df7a4439a99f69b329521983299c1be468b5ea04a
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.12
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Jun 3, 2026.
Transparency log