so what's the point of containers here? seems only to make things less transparent and more complex to manage.
js scripts running on frameworks running inside containers
PS so I see the host ended up staying uncompromised