LXD does at least (unlike docker) default to unprivileged containers
I get that containers will always have a larger attack surface than Xen/KVM. Just thought it was worth mentioning that some container approaches are thinking about security more than others.
It's a trade off, but one that seems to trend towards more secure despite potentially a few quirks.