use the latest kernel • Performance and stability issues with old kernels Container Isolation • Using cgroup doesn’t guarantee resource isolation • We are working on better I/O performance • https://sysdig.com/blog/container-isolation-gone-wrong/ Performance • Docker is not slow • I/O penalty in CoW is small • CircleCI DB images with optimizations