Can you suggest any preferred alternative methods of isolation that offer similar efficacy and ease of use for quickly running complete software systems made by an unknown/untrusted actor?
It can. I think it's fair to assume that the standard developer setup to let them be productive is not this proper configuration.
> Can you suggest any preferred alternative methods of isolation that offer similar efficacy and ease of use for quickly running complete software systems made by an unknown/untrusted actor?
No. It's a hard problem! If it was easily solved we wouldn't be seeing all this development surrounding e.g. WebAssembly
While I agree that Docker as written isn’t good at security, your post has big “they’re holding the iPhone wrong!” vibes — and seemingly ignores the historic reasons that people would think it provides security.
More like "it just isn't meant to be used for that". At least not in the default configuration, and that's fine!
> seemingly ignores the historic reasons that people would think it provides security
I've been using docker since it was announced. People have always been very clear that docker is not a security boundary, at least not with its default configuration.
I’ve also used it since the beginning and that’s some mighty strong revisionism.
Docker was compared to VMs — with a tiny asterisk of fine print that it’s not actually configured to employ security features it’s built with.
By certain people, yes. They have always been wrong. Never by the docker team themselves.