Almost every service I self-host runs in a Linux container, and the math just doesn't favor a VM anymore
…Not every isolated process needs its own guest operating system, and unprivileged containers go a long way to bridging that gap and ensuring that a container only has the access it needs…