FTL is a new operating system architecture designed for cloud environments that reimagines how containers isolate and manage resources. According to the FTL project, the system allows developers to build their own operating system as a library, fundamentally changing how OS-level features are implemented.

At its core, FTL uses a userspace OS design where each container runs its own OS implementation as a shared library. This library implements most traditional OS concepts—including Linux processes, virtual filesystems (VFS), and TCP/IP networking. The FTL kernel provides a minimal interface to implement Linux system calls in userspace, similar to how a hypervisor operates.
A key technical difference from conventional container systems is FTL’s isolation mechanism. According to the project, the FTL kernel isolates containers better than existing monolithic kernels through a hypervisor-like interface based on lightweight hardware-based isolation in user mode. This approach offers VM-like security levels without requiring dedicated bare-metal machines for each container.
FTL maintains backward compatibility with Linux applications. The project demonstrates this by running a Rust-based HTTP server—a standard Linux application—on FTL. However, the architecture also supports specialized unikernel-like applications that don’t require POSIX abstractions, offering developers flexibility in how they structure their software.
The design philosophy combines principles from both microkernel and monolithic kernel architectures. According to FTL’s documentation, the goal is to make lightweight containers as secure as virtual machines while unlocking new OS-level capabilities in applications without sacrificing performance.
A significant advantage of the userspace OS model is simplified maintenance and extension. Since the OS operates as a library rather than a kernel component, developers can add features, apply security updates, and extend functionality without kernel programming or eBPF (extended Berkeley Packet Filter) modifications. This approach treats OS development similarly to application development, potentially reducing complexity and improving iteration speed for cloud infrastructure teams.
Key facts
- FTL allows developers to build operating systems as userspace libraries within containers
- The architecture provides hypervisor-like isolation using lightweight hardware-based isolation in user mode
- FTL maintains compatibility with Linux binaries and system calls
- Each container in FTL runs its own userspace OS implementation
- The design combines microkernel flexibility and security with monolithic kernel performance and simplicity
- OS features can be extended without kernel programming or eBPF modifications
