so what's the point of containers here? seems only to make things less transparent and more complex to manage.

js scripts running on frameworks running inside containers

PS so I see the host ended up staying uncompromised