Docker containers use Linux kernel features to create an isolated environment, running on the same machine as docker is. This creates a virtual machine, with its own kernel, and runs the container in there. This gives stronger isolation and security guarantees.
That depends on the runtime though. For example, libkrun lets you do this:
docker run --runtime krun hello-world
That starts/runs the OCI in a qemu microvm.
I have the same question as GP. Your answer helps a little but not really. I might be naive, but I was under the impression that malicious code escaping a docker image and running amok on my host system was not something I should be too worried about. Especially if I run docker in rootless mode. Is that wrong?
For clarity I’m actually using podman, not Docker.