Containers rely on many privilege separation systems to do what they do, they are in fact a rather extreme case of multi-user systems, but they tend to present as “single” user environs to the container’s processes.
Are they? My understanding was that by default, the `dockerd` (or whatever) is root and then all containers map to the same non-privileged user.