I don’t understand the last part/decision to start containers operating in a firecracker VM on an ec2 host . Could they use ec2 .metals for security and just invoke a docker container ?

I mean I’m aware of container escapes but how common are they really especially if you have a WAF in front of the service

