I was always taught that Docker is not suitable for securely separating stuff, just for compartmentalisation. Something about running as root iirc?
The daemon runs as root, so your containers are only as secure as the daemon itself.
> The daemon runs as root, so your containers are only as secure as the daemon itself.
This is not correct. The daemon only starts and monitors processes in this case. You can start a process as a different user. You can also use user namespaces to make "root in the container" not root on the host.
This did not automatically lead to allow a contained user to breakout, but made it easier.
In 1.10 user namespacing reduces this risk as the root user in a container can be remapped to another user account outside the container.