cgroups, seccomp etc are set by docker so they do work. I think it is weird to view these as exclusively owned by the init process.
Docker works on systems without systemd (indeed, it runs on Windows), so relying on features that systemd has (currently, many are only recent additions) is not really an option.
Docker works on systems without systemd (indeed, it runs on Windows), so relying on features that systemd has (currently, many are only recent additions) is not really an option.