https://ashishb.net/programming/run-tools-inside-docker/
It does reduce the attach surface drastically.