Acceptance test results for each GA release, run on real AWS infrastructure.
| Capability | Community | PRO |
|---|---|---|
| Core VM lifecycle | ||
| MicroVM create, run, terminate | ✓ | ✓ |
| MicroVMImage build from Dockerfile | ✓ | ✓ |
| Memory sizing (256 MiB – 32 GiB) | ✓ | ✓ |
| Idle auto-suspend & auto-resume | ✓ | ✓ |
| Drift detection & VM re-creation | ✓ | ✓ |
| MicroVMClass (instance templates) | ✓ | ✓ |
| Scaling | ||
| MicroVMReplicaSet (pool management) | ✓ | ✓ |
| Scale up / scale down | ✓ | ✓ |
| Rolling update (new image version) | ✓ | ✓ |
| Networking | ||
| Internet egress (default) | ✓ | ✓ |
| VPC egress (private network connector) | ✓ | ✓ |
| MicroVMNetwork CRD | ✓ | ✓ |
| Security & access control | ||
| RBAC — per-VM ServiceAccount tokens | ✓ | ✓ |
| Sidecar token injection (pod annotation) | ✓ | ✓ |
| ARN collision prevention (webhook) | ✓ | ✓ |
| Admission webhook validation | ✓ | ✓ |
| PRO — Gateway & load balancing | ||
| MicroVMGateway (session-affine HTTP proxy) PRO | — | ✓ |
| Round-robin load balancing across pool PRO | — | ✓ |
| Session lifecycle (202 Resuming, max duration) PRO | — | ✓ |
| Token cache pre-warming PRO | — | ✓ |
| PRO — Multi-tenancy | ||
| Cross-namespace isolation (tenants cannot cross) PRO | — | ✓ |
| Namespace-scoped gateway access control PRO | — | ✓ |
| MicroVMImageBinding / cross-namespace imageRef PRO | — | ✓ |
| MicroVMImagePolicy (image governance) PRO | — | ✓ |
| QS-00 | Installer download and checksum |
| QS-01 | Operator running |
| QS-02 | Namespace labelled for MicroVMs |
| QS-03 | MicroVMImage created and built |
| QS-04 | MicroVM created and running |
| QS-05 | MicroVM list shows VM |
| QS-06 | Token via --direct flag |
| QS-07 | Curl endpoint returns OK |
| QS-08 | Teardown — delete VM |
| RBAC-01 | ServiceAccount created |
| RBAC-02 | Role with resourceNames |
| RBAC-03 | RoleBinding created |
| RBAC-04 | Auth can-i with subresource |
| RBAC-05 | Authorised SA gets token |
| RBAC-06 | SA rejected for different VM |
| RBAC-07 | Unauthorised SA rejected |
| RBAC-08 | Unlabelled namespace rejects VM |
| NET-01 | Internet egress — public internet |
| NET-02 | Default egress has internet access |
| NET-03 | MicroVMNetwork becomes Active |
| NET-04 | VPC egress VM connects |
| NET-05 | Network list shows connector |
| INJ-01 | Namespace has injection label |
| INJ-02 | SA and RBAC created |
| INJ-03 | Annotated pod created |
| INJ-04 | Sidecar container injected |
| INJ-05 | Token volume present |
| INJ-06 | Token files written |
| INJ-07 | Auth token non-empty |
| INJ-08 | Token works to call MicroVM |
| INJ-09 | No-RBAC pod has empty token dir |
| RS-01 | ReplicaSet creates 3 MicroVMs |
| RS-02 | RS list shows ReplicaSet |
| RS-03 | Scale up to 5 |
| RS-04 | Scale down to 2 |
| RS-05 | Rolling update changes ImageRef |
| RS-06 | Delete terminates all VMs |
| CLASS-01 | MicroVMClass created |
| CLASS-02 | VM inherits class values |
| CLASS-03 | Spec shows all inherited values |
| CLASS-04 | User override takes precedence |
| CLASS-05 | kubectl get lists class |
| CLASS-06 | Non-existent class rejected |
| DRIFT-01 | External termination detected |
| DRIFT-02 | Operator re-creates VM with new ID |
| AUTO-01 | VM suspends after idle duration |
| AUTO-02 | Auto-resume on traffic |
| AUTO-03 | Operator does not fight idle policy |
| MEM-01 | 4096 MiB image correct status |
| MEM-02 | No memorySizeMiB defaults to 2048 |
| MEM-03 | Invalid memorySizeMiB rejected |
| MEM-04 | memorySizeMiB immutable on update |
| MEM-05 | CLI describe shows memory |
| MEM-07 | Run VM from 4096 MiB image |
| ADM-01 | Missing idle policy rejected at admission |
| ADM-02 | Idle duration below minimum rejected |
| ADM-03 | Maximum duration above 28800 rejected |
| ADM-04 | ClassName bypasses idle policy requirement |
| ADM-05 | Valid idle policy accepted |
| ADM-06 | Failed creation stays in Failed state |
| ADM-07 | Failed creation retries after spec change |
| ADM-08 | Duplicate-named MicroVMImage rejected by webhook |
| ADM-09 | Delete blocked by running VMs emits Warning event |
| CS-01 | PRO operator running |
| CS-02 | Community CRDs installed |
| CS-03 | PRO CRDs installed (MicroVMGateway) |
| CS-04 | Session namespace ready |
| CS-05 | Pod Identity association exists |
| GW-01 | ReplicaSet pool created |
| GW-02 | Pool VMs reach Running state |
| GW-03 | Gateway CR created |
| GW-04 | Gateway reaches Ready state |
| GW-05 | Gateway service endpoint exists |
| GW-06 | Gateway delete removes all resources |
| GW-07 | Gateway spec replicas scales deployment |
| GW-08 | Gateway status reflects readiness |
| MT-01 | Tenant A cannot access Tenant B gateway |
| MT-02 | Tenant B cannot access Tenant A gateway |
| MT-04 | Valid SA accesses its own namespace gateway |
| MT-05 | Operator watches only labelled namespaces |
| RR-01 | Round-robin gateway reaches Ready |
| RR-02 | Requests cycle through all pool VMs |
| RR-03 | No session stickiness between requests |
| RR-04 | Token cache pre-warmed for all VMs |
| RR-05 | X-Served-By-VM header on every response |
| NEG-01 | Non-existent pool — gateway stays DOWN |
| NEG-02 | Pool scaled to zero — 503 |
| NEG-03 | Pool deleted — gateway recovers |
| NEG-04 | Token cache miss returns 503 not 500 |
| NEG-05a | Missing auth header returns 401 |
| NEG-05b | Malformed bearer token returns 401 |
| NEG-06 | Cross-namespace SA token rejected |
| NEG-07 | VM fails mid-session — assignment cleared |
| SL-01 | Idle timeout triggers VM suspension |
| SL-02 | Suspended VM returns 202 Resuming |
| SL-03 | Retry after 202 returns 200 once Running |
| SL-04 | Max session duration forces release |
| SL-05 | SuspendOnIdle=false — VM stays Running |
| IMG-01 | Duplicate-named image rejected by webhook |
| IMG-02 | Cross-namespace imageRef + Binding unaffected |
| IMG-03 | Delete blocked — emits event + bounded retries |