The credentials part...
https://docs.docker.com/ai/sandboxes/security/credentials/
It seems to do a good job of not stating the actual threat model anywhere.
It seems to do a good job of not stating the actual threat model anywhere.