I had the very same feeling. Containers are very useful, but the Docker suite of tools just don't have a very good security story.
Now you say something of substance!