Oh... these are inside a docker container... that sounds ripe for a kernel privesc -- Also its not /real/ root :V
Better term would be disposable root shell. I am interested in the networking part of it. How that is achieved.
GitHub repo https://github.com/hackerschoice/segfault
Not sure if it covers your question though.