Embed isolated microVM sandboxes directly in your Python code — local (embedded) or smolfleet cloud.
Project description
smol — Python SDK
Embed isolated microVM sandboxes directly in your Python code. Same API
locally (embedded engine, no server) or against the smolfleet cloud — the
backend is chosen via ConnectOptions / SMOL_CLOUD_TOKEN. Mirrors the
Node SDK.
Supported platforms (native local transport): macOS Apple Silicon, and Linux x64/arm64 with glibc ≥ 2.34 (RHEL 9, Ubuntu 22.04+, Debian 12, Amazon Linux 2023; the wheel is tagged
manylinux_2_34). The cloud transport works anywhere the wheel installs. Not yet published: macOS Intel, and glibc < 2.34.
from smol import Machine, MachineConfig, ResourceSpec
# Local (embedded microVM) — boots in-process, no server.
with Machine.create(MachineConfig(resources=ResourceSpec(cpus=2, memory_mb=1024, network=True))) as m:
res = m.run("python:3.12", ["python", "-c", "print(2 ** 10)"])
res.assert_success()
print(res.stdout) # 1024
m.write_file("/tmp/in.txt", "hi")
print(m.read_file("/tmp/in.txt").decode())
# Cloud (smolfleet) — same API, just point at the cloud.
from smol import ConnectOptions
with Machine.create(
MachineConfig(image="alpine:3.20"),
ConnectOptions(target="cloud", api_key="smk_…"), # or set SMOL_CLOUD_TOKEN
) as m:
print(m.exec(["echo", "hi"]).stdout)
Async: AsyncMachine (non-blocking)
Machine is synchronous — each call blocks the calling thread. When you're
driving many machines from one event loop (a fleet of disposable workers), use
AsyncMachine: the same API, but every I/O method is a coroutine that runs
off the loop, so launches and calls overlap instead of serializing.
import asyncio
from smol import AsyncMachine, MachineConfig, ConnectOptions, PortSpec
async def main():
cfg = MachineConfig(image="alpine:3.20", ports=[PortSpec(host=8080, guest=8080)])
conn = ConnectOptions(target="cloud") # or SMOL_CLOUD_TOKEN
# Launch a fleet concurrently — none blocks the loop.
machines = await asyncio.gather(*(AsyncMachine.create(cfg, conn) for _ in range(8)))
try:
await asyncio.gather(*(m.wait_until_ready() for m in machines))
# Reach a service inside a vm via the authed connect bridge (no tunnel):
health = await machines[0].request(8080, "healthz")
finally:
await asyncio.gather(*(m.delete() for m in machines))
asyncio.run(main())
Every Machine method has an awaitable counterpart on AsyncMachine
(create/connect/exec/wait_until_ready/request/fork/…), plus
async with for auto-delete. endpoint(port) stays synchronous — it only builds
a URL and does no I/O.
Architecture
- Pure-Python layer (
python/smol):Machine, transports, types, errors — zero third-party deps (the cloud transport uses onlyurllib). - Native core (
src/lib.rs, cratesmol-py): apyo3extension that links thesmolvmengine in-process for the local path — the Python analogue of thesmol-nodeNAPI crate. The local API is synchronous (the engine blocks). - Cloud transport: a REST client to smolfleet
/v1whose request/response shapes match smolfleet's OpenAPI contract (Bearersmk_…).
Disposable workers: wait for ready, then connect (cloud)
Launching a machine as a disposable agent runtime has two easy-to-miss steps; both are first-class here.
Machine.create() already waits for the machine to be ready — not merely
started. state == "started" means the VM process launched; the guest is
still booting and is not usable yet. Acting on started is the classic
teardown race (works on a slow cold start, times out on a warm one). Gate on the
unambiguous signal:
with Machine.create(
MachineConfig(image="alpine:3.20", ports=[PortSpec(host=8080, guest=8080)]),
ConnectOptions(target="cloud"),
) as m:
m.wait_until_ready() # create() already waited; re-assert if reconnecting
print(m.ready(), m.ready_at())
# Reach a service INSIDE the vm through the authenticated connect bridge —
# no Cloudflare/localhost.run tunnel, no public exposure, no egress allow-list.
# Have the worker LISTEN on a published port and connect *inbound*:
print(m.request(8080, "healthz").decode()) # authed HTTP to the guest port
ep = m.endpoint(8080, "/socket") # or build a ws:// url for your ws client
# websocket.connect(ep.ws_url, additional_headers=ep.headers)
API
Machine(sync) /AsyncMachine(awaitable, non-blocking) — identical surface; see the async example above.Machine.create(config=None, conn=None)— create and start a machine.machine.exec(command, opts=None)/machine.run(image, command, opts=None)→ExecResultmachine.read_file(path)→bytes/machine.write_file(path, data, mode=None)machine.ready()/machine.ready_at()/machine.wait_until_ready(timeout_s=120, interval_s=1)(cloud)machine.endpoint(port, path=None)→PortEndpoint/machine.request(port, path=None, method="GET", data=None)→bytes(cloud connect bridge)machine.pull_image(image)/machine.list_images()(local)machine.stop()/machine.delete()/machine.state()- Use it as a context manager to auto-
delete()on exit. - Errors are typed:
SmolError(with.code),ExecutionError,NotSupportedError,InvalidConfigError.
ExecResult has .exit_code, .stdout, .stderr, .success, .output, and
.assert_success().
Install / build from source
The cloud path is pure Python. The local path needs the native extension, which
links libkrun from the sibling smolvm repo (three levels up).
python -m venv .venv && . .venv/bin/activate
pip install maturin
# Build + install the native extension (points at the repo's bundled libkrun):
LIBKRUN_BUNDLE=../../../lib maturin develop
To boot local microVMs the engine needs a code-signed boot helper carrying the
macOS com.apple.security.hypervisor entitlement (the Python process itself does
not). Point it at one (and the libkrun dir):
SMOLVM_BOOT_BINARY=../../../target/release/smolvm \
SMOLVM_LIB_DIR=../../../lib \
python your_script.py
On Linux the host needs /dev/kvm.
Tests
python tests/test_unit.py # error parsing + path encoding (no VM/network)
python tests/test_cloud_mock.py # cloud transport vs a mock /v1 (no VM/network)
python tests/test_async_mock.py # AsyncMachine vs a mock /v1 (concurrency, no VM/network)
# Local VM boot (needs the native build + the env above):
SMOLVM_BOOT_BINARY=… SMOLVM_LIB_DIR=… .venv/bin/python tests/test_local_e2e.py
License
Apache-2.0
Project details
Release history Release notifications | RSS feed
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distributions
Built Distributions
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file smolmachines-1.6.12-cp39-abi3-manylinux_2_34_x86_64.whl.
File metadata
- Download URL: smolmachines-1.6.12-cp39-abi3-manylinux_2_34_x86_64.whl
- Upload date:
- Size: 50.5 MB
- Tags: CPython 3.9+, manylinux: glibc 2.34+ x86-64
- Uploaded using Trusted Publishing? Yes
- Uploaded via: twine/6.1.0 CPython/3.13.14
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
c88f92cfb9fcfaeed7fc06f86503dad16aab0dc7613577ada2437e6f9f84b161
|
|
| MD5 |
9eb5039fb96ce172e7ad963722540144
|
|
| BLAKE2b-256 |
12531dbff17060ab2bbabed434d1f9aeb110efd828f0465ee0795de5d2e9f53f
|
Provenance
The following attestation bundles were made for smolmachines-1.6.12-cp39-abi3-manylinux_2_34_x86_64.whl:
Publisher:
release.yml on smol-machines/smol
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
smolmachines-1.6.12-cp39-abi3-manylinux_2_34_x86_64.whl -
Subject digest:
c88f92cfb9fcfaeed7fc06f86503dad16aab0dc7613577ada2437e6f9f84b161 - Sigstore transparency entry: 2220276416
- Sigstore integration time:
-
Permalink:
smol-machines/smol@3745d79baeded942e91327afe84c00a382424b1e -
Branch / Tag:
refs/tags/v1.6.12 - Owner: https://github.com/smol-machines
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
release.yml@3745d79baeded942e91327afe84c00a382424b1e -
Trigger Event:
push
-
Statement type:
File details
Details for the file smolmachines-1.6.12-cp39-abi3-manylinux_2_34_aarch64.whl.
File metadata
- Download URL: smolmachines-1.6.12-cp39-abi3-manylinux_2_34_aarch64.whl
- Upload date:
- Size: 49.4 MB
- Tags: CPython 3.9+, manylinux: glibc 2.34+ ARM64
- Uploaded using Trusted Publishing? Yes
- Uploaded via: twine/6.1.0 CPython/3.13.14
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
432abd9fc3e60945624be00b580859a5877cb292bde86c4c883604f460805fda
|
|
| MD5 |
d44057ab7550c82c169b200b94a7e9ec
|
|
| BLAKE2b-256 |
09abbe86728f979a4538c70ab941da834a29fc32a485f10a64d2bdfec7375f85
|
Provenance
The following attestation bundles were made for smolmachines-1.6.12-cp39-abi3-manylinux_2_34_aarch64.whl:
Publisher:
release.yml on smol-machines/smol
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
smolmachines-1.6.12-cp39-abi3-manylinux_2_34_aarch64.whl -
Subject digest:
432abd9fc3e60945624be00b580859a5877cb292bde86c4c883604f460805fda - Sigstore transparency entry: 2220277582
- Sigstore integration time:
-
Permalink:
smol-machines/smol@3745d79baeded942e91327afe84c00a382424b1e -
Branch / Tag:
refs/tags/v1.6.12 - Owner: https://github.com/smol-machines
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
release.yml@3745d79baeded942e91327afe84c00a382424b1e -
Trigger Event:
push
-
Statement type:
File details
Details for the file smolmachines-1.6.12-cp39-abi3-macosx_11_0_arm64.whl.
File metadata
- Download URL: smolmachines-1.6.12-cp39-abi3-macosx_11_0_arm64.whl
- Upload date:
- Size: 40.5 MB
- Tags: CPython 3.9+, macOS 11.0+ ARM64
- Uploaded using Trusted Publishing? Yes
- Uploaded via: twine/6.1.0 CPython/3.13.14
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
5c5bef68b7813b257dae4ae766827fad87210fb3c499d2c72bdd8f04f63ea200
|
|
| MD5 |
42d054eac4c705ea1f03dadeb7f237a5
|
|
| BLAKE2b-256 |
d2635563a008a5bf9fcab09b48ab01676130020a2204227b850d385b112e049f
|
Provenance
The following attestation bundles were made for smolmachines-1.6.12-cp39-abi3-macosx_11_0_arm64.whl:
Publisher:
release.yml on smol-machines/smol
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
smolmachines-1.6.12-cp39-abi3-macosx_11_0_arm64.whl -
Subject digest:
5c5bef68b7813b257dae4ae766827fad87210fb3c499d2c72bdd8f04f63ea200 - Sigstore transparency entry: 2220276911
- Sigstore integration time:
-
Permalink:
smol-machines/smol@3745d79baeded942e91327afe84c00a382424b1e -
Branch / Tag:
refs/tags/v1.6.12 - Owner: https://github.com/smol-machines
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
release.yml@3745d79baeded942e91327afe84c00a382424b1e -
Trigger Event:
push
-
Statement type: