I agree with you that VMs would provide better isolation. But I do think containers (or other kernel techniques like SELinux) can still provide quite decent isolation with a very limited performance/ease-of-use cost. Much better than nothing I'd say?
eyberg|6 months ago
christophilus|6 months ago
A locked door is better than an unlocked one, even if it gives its owner a false sense of security. There is still non-zero utility there.
bryceneal|6 months ago