Application Containers like LXD, Docker and rkt are popular ways of containerization of each application. Since, buzzword period is over, it is time to properly discuss application container security and challenges in properly implementing isolation on the application container level.Which application container should I check out from a security perspective ? What security controls are there? What is missing? What could be better? Are there any best practices already? What about tools?