I switched from Docker to Podman and the real security upgrade was going rootless

Going rootless shrank what a compromised container could do to the host.