The containerizing is almost a capability based security system. Instead of adding that layer to block everything except a certain resource, why not change the defaults in the OS so that it defaults to NO access instead? Saves resources, provides much better security.