Container Security

Principle: never expose the Docker socket directly; gate it with least privilege (e.g. docker-socket-proxy).