DDoS attacks have been on the rise, I work at a hosting provider and last year we only saw somewhere around a thousand attacks, now we're seeing that monthly...
Isn't it possible that the traffic could just be going over an MPLS backbone? If that's the case, then there could potentially be more hops that aren't seen.
I use Docker in 'production' as the backend for an internal training tool. Docker improves my quality of life as a developer so much. Wrapping previously difficult to work with simulations into easily manageable and API driven containers is awesome!