even with docker's user namespacing it's a good idea not to run as root in the container when possible