Joyent, our one example of Solaris-style containers?
I think there is wide acceptance of the notion that Solaris containers, on which SmartOS and SmartData Center are based, were designed with security in mind and can be used in a multi-tenant environment. Linux containers, on the other hand, will be presumed leaky until proven otherwise and of uncertain value in multi-tenant environments. That is, you need to know none of the other tenants is hostile to run them in multi-tenant mode. One way to use Linux containers would be for one customer to put many containers on one server, no other tenant allowed. What's intersting about Joyent is it's got both containers and Solaris-style security on the containerized host. Google knows containers, but it's still keeping Linux containers inside a virtual machine, I believe, except in its internal operations.