why isn't docker and k8s banned by security teams? these are clearly broken abstractions that would violate most security audits immediately
But containers themselves should not -- there are plenty of security benefits to using containers. There is no real difference between an LXC container and a runc container besides the fact that Docker defaults to running thing as root and without user namespaces. That is obviously a bad decision, but it's not an indictment of containers as a concept.
Like most good stories, there's a beginning, middle, and end. We're in the middle now, and Fargate uses both regular EC2 instances and Firecracker in some cases.