Good read on the security & spectre mitigations (v8 isolates, no native code, limiting API surface that provides timing, isolating workers with high cpu usage) used for cloudflare workers

You can also view it as (an example of the) functions as a service security model. Where this one is sharing worker processes between tenants instead of routing requests to a single instance.

