Why do actions use VM’s instead of containers? And yet codespaces use containers.
It can be secured, as gitpod does, but as I understand it is a PITA.
I always thought this was a hard limitation, but I deployed some self-hosted GHA runners in Kubernetes this week and to my surprise that setup came with an option to run the full docker daemon inside of a container - so apparently it is possible.
Rootless containers are a lot of work and do not support many scenarios that you're going to need.
MicroVMs are the same experience as GitHub, full system and Kernel, do what you will. Even launch a nested VM.
I haven't tried more than three levels but in theory more should work.
What is Docker in Docker?
Although running Docker inside Docker is generally not recommended, there are some legitimate use cases, such as development of Docker itself.
...If you are still convinced that you need Docker-in-Docker and not just access to a container's host Docker server, then read on.
This makes it pretty clear that it's a different copy of the docker daemon (which eg. allows you to test changes to docker itself) and specifically says it's different from "just access to a container's host Docker server".