I know the phusion/baseimage argues against excessive isolation:
https://github.com/phusion/baseimage-docker#docker_single_pr...