software running in docker's a bit more sandboxed than running outside of it, even if it's not bulletproof.