You run a container as root. That sounds dangerous. But here's a more interesting question: Which root? Root inside the container? Root on the host? Or the root user running the Docker daemon? They aren't necessarily the same thing. And understanding that difference changes how you think about Docker security. We've already seen that containers rely on namespaces, capabilities, seccomp, and other Linux mechanisms for isolation. Now let's go one level deeper. W...