Measurements. Where every number on this site comes from.

Every number on this site comes from a recorded run on our own hosts, between 27 and 30 Sep 2026. If a number is not on this page or on Compatibility, it is not on the site. None of these runs is a load test: each measures one build at a time on a development host.

Through the public API, 28 Sep 2026

The karts CLI on a Mac, through the public API at api.karts.kartikey.fyi, to our dev host running the same stack as the first run below, in the same development mode. Wall is the CLI's own time; server is the host's build time.

RunResultWallServer
feature/refundsTiny Shop branch with a new migration, on a quiet host: ready; restore 16 ms, clone_init 111 ms, migrations 166 ms, ready 723 ms2.23 s1.08 s
mainTiny Shop, template rebuilt for a new image: ready; template 6.3 s9.00 s7.48 s
main, day beforeTiny Shop, first build: ready; template 10.5 s13.7 s12.0 s
feature/cleanupdrops customers.notes: refused; no environment left behind2.00 s—
split-shopa web and an API service in one environment: both answer; the web page renders the API's products10.17 s8.07 s
shop-fronta frontend project linked to Tiny Shop: its server-side call reached the backend over the private link6.20 s4.55 s
POST after idle5 POSTs to the API, each after 7 s idle: 5/5 answered 200——
host restartwith 4 environments serving: every URL answered 200 again without a new karts up, the link included; the edge answered 502 for about 4.4 s during the restart——
Miniflux maina Go app, first build: ready; template 46.4 s, go build 44.8 s94.23 s91.64 s
Miniflux branchadds a Go migration: ready, migration applied; go build 45.2 s with a cold build cache48.68 s45.72 s
project deletekarts project delete: deleted, and the project's place reused3.89-6.15 s—

A first karts up of Tiny Shop, template included, took 9.00 s and 13.7 s in these two runs. Apps with larger installs take much longer: see Compatibility.

The first end-to-end karts up, 27 Sep 2026

The karts CLI on a Mac, the control API, the host daemon, a Firecracker micro-VM with its own Postgres, and a public URL with a Let's Encrypt certificate issued on demand. The app is Tiny Shop, our sample Node and Postgres app. The CLI reached the control API over our own private network, not the public API.

Mode. In every run on this page the host daemon ran as an ordinary user: user namespaces, no jailer, no per-VM firewall rules. Everything else was the production code path. The runs are to be repeated under the jailer. See Security.

RunResultCLI wall timeServer build
main, first everBuilt the template (10 migrations, seed of 40 customers and 160 orders), ready at main-1add.karts.kartikey.fyi29.7 s27.8 s (template 26.4 s)
feature/refundsAdds 0011_create_refunds.sql; ready at feature-refunds-fc00.karts.kartikey.fyi2.3 s1.26 s
feature/discountsAlso adds a 0011; refused: "migration 0011 is already taken by branch feature/refunds; renumber to 0012 or later"< 1 snone
feature/cleanup0012 drops customers.notes; refused: "destructive migration refused … ALTER TABLE customers DROP COLUMN notes — drops column customers.notes and every value in it"< 1 snone

Server steps of the feature/refunds build, as karts up --timings prints them. Install took 0 ms because the dependencies came from the cache.

    disks             1 ms
    restore          16 ms
    clone_init      112 ms
    files             8 ms
    install           0 ms
    migrations      230 ms
    ready           881 ms

The first request to a new URL took 5.5 s, including issuing its certificate. Later requests took ~0.5 s.

Snapshot restore on the host

Firecracker v1.17.0 on our KVM host, an Intel Core i5-10300H with an NVMe disk, before any of Karts ran on it. A guest was booted once and snapshotted; then new VMs were restored from that snapshot, one after another.

MeasureResult
Snapshot restore to a running guest10.7 ms median, 13.2 ms p95, over 100 runs
Private host memory per restored VMabout 19 MiB
Copy-on-write copy of a 1 GiB disk1.4 ms median
Cold boot to guest userspace1,067 ms median; 312 ms with two kernel arguments and quiet
Kernel random generator reseeded after restorein all 110 clones

Restore alone excludes the jailer, networking, vsock, clone initialisation and the app. The end-to-end run above includes them, apart from the jailer and the per-VM firewall rules.