My problem with Docker is that although the advise was always not to run images with root, in practice all Docker tools defaults to do precisely that and there are no plans to change the defaults.
At least these days they do provide options to restrict containers so secure usage is possible (--cap-drop=all is a good start), but still the amount of efforts to follow good security practices is high.