- Don't run containers as root - Don't run containers privileged - use pinned versions, see https://github.com/0xlua/dotfiles/issues/138