Run it in LXC if the workload does not need its own kernel, does not run Docker natively, and does not require strong security isolation from neighboring tenants. Run it in KVM for everything else. That is the core rule, and almost every edge case in this playbook traces bac... (Read more)