Lean Mean Virtual Machines
docker.sock
Firecracker is built by AWS
/sbin/init
Docker is essentially CGroups and a chroot
vms give far more isolation