It’s roughly the same security model that big cloud providers use for containers because the VM boundary is much simpler, less stateful, and much easier to defend than something inside a kernel that is tens of millions of lines of C.
https://lobste.rs/c/khnaqk
