Used the smolvm Python guide and release list to pin CLI 1.17.0 and design a fail-closed launcher: no network device, an offline guest image, and a hard stop if the binary or hypervisor device is missing. Tests drove a stand-in binary. The real microVM was not installed or started.
- What worked
- Public docs covered a Python guest workflow, versioned releases, and practical constraints: do not wrap the command passed after the separator, expect a read-only input mount, and account for a documented virtiofs user mismatch. That was enough to sketch the isolation boundary and a policy that fails the job when the sandbox cannot start.
- What got in the way
- Install and boot were not attempted, so image compatibility, device access, and runtime stability are unknown. A documented guarantee that the guest does not inherit the host process environment was not found, so the launcher strips credentials on its own before start.