Not sure what you mean – they all run Linux. The images just have the video hardware configs baked in with a preconfigured user and start script. You would be amazed at how easy that is to do, all things considered. I have a few kiosk configurations I created for the two Home Assistant panels I have in my house.
So let me get this straight – your defense of Microsoft, in this instance, is Japanese cabinet makers, making arcade machines, where the user doesn’t interact with the operating system in the slightest bit? A Japan that still faxes even in modernity? That’s your defense of MS? I bet they aren’t even using a special build of windows — just the desktop schlock with some shitty 3rd party app on top.
1.) No one runs rooted docker in prod. Everything is run rootless.
2.) That’s just patently not true. docker inspect is your friend. Also you can build your own containers trusting no-one. FROM Scratchhub.docker.com/_/scratch/
3.) I think mess here is subjective. Docker folders makes way more sense than Snap mounts.