Securing docker, with it's weird iptables shenanigans is a nightmare. I prefer to use rootless podman, and also avoid exposing ports (by using internal routing and if needed, a reverse proxy with only one published port)
Agreed that podman has been a great experience in comparison.
It's a neat trick for development environments but for real traffic you'll still have to actually do the iptables BS.
It is performant enough for my usecase: services used by me and a few friends.
I don't use the root mode, but I was under the impression it doesn't have the same well known docker issue where it exposes everything on the public interface(and using a firewall on top of it is complicated)
You need a last resort security control against stuff like this anyway. Even an automation failure or misunderstanding of a ruleset can leave you exposed.
Security must be layered.