Skip to main content
k7 logo

k7 is self-hosted infra for secure VM sandboxes — orchestrated with Kubernetes, driven by a CLI, REST API, and Python SDK. Pick a backend per sandbox: Firecracker via Kata (kfd), QEMU + Longhorn (kql), k7d for warm CoW forks in milliseconds, or k7d-fc — the same k7d daemon driving jailed Firecracker. Run docker build inside any of them with --docker; sandboxes are locked away from the platform by default and reachable only through the ports you open.