A detail step to run desktop environment in container

I didn’t write about wanting to add compositor, you must have misread something.

Use the security you need, not more. That’s my approach here. If it’s as secure as a non-virtualized system with similar setup that’s fine.