Making Containers More Isolated: An Overview of Sandboxed Container Technologies
unit42.paloaltonetworks.com
unit42.paloaltonetworks.com
In the case of this article, in the Docker section there's no mention of the Apparmor/SELinux policy that gets applied to containers and no mention of the seccomp policy that's used by default to constrain some syscalls from a running container.
My general take on it is that Docker/LXC provide quite flexible security models, which can be modified to suit a user's process (e.g. by dropping unneeded capabilities from the default set or adding a custom seccomp profile)
gvisor provides a higher level of security due to additional layers being in place and once the Google team move to regular releases with a support lifecycle, I think it'll be quite a good option where it works to provide additional isolation for production workloads (for some production environments, the idea of picking a nightly build to use might not fit too well)
One tradeoff to consider for things like gVisor/kata/firecracker is that they don't have the same composable security model used in standard linux containers, so it's not always possible to remove a single part of the isolation (e.g. running with host networking) whilst leaving the rest of it in place
The idea was that such a packaged system should be doing all the security things you'd do if running on the bare operating system. So getting root inside a container would be expected to be as devastating as if the host had been compromised. Admittedly many developers didn't get this memo in the beginning.
As to root in a container == host compromise, what makes you say that? Absent a Linux kernel vuln. or mistake when running the container that's generally not easily possible.
(that's not to say that containers should be run as root, they should not, but that it's not necessarily trivial to breakout of one)
By default there is no user mapping.
And in contrast with another commenter here, I'm glad this was a to-the-point, no nonsense article - no stupid GIFs or too many cringey attempts at humour.