I'm thinking of the mass of "single function per server" virtual machines which really do nothing in terms of memory and CPU that a PCI DSS certification entails, the NTP server, central authentication, DNS, jump host, local OS package repos etc etc,
can those be summarized in a one VMWare box with a bunch of containers on? In much the analogue way a bunch of VMWare boxes can be squeezed into a single hypervisor?
I know this stuff could end up deeply "in the eye of the beholder/QSA" area, but I'm either hoping to find out that "no, because..." or "yes, I've done it" kind of answer. Also, "I don't see why not" from someone deep into docker and with PCI experience would also be nice ^_^
UPDATE 1, Docker security docs