This article delves into the challenges posed by SELinux Multi-Category Security (MCS) on GitLab runner's architecture, particularly when using containers and shared volumes. It discusses the MCS mechanism, its implications for cross-container file access, and explores potential solutions such as microVM isolation with Cloud Hypervisor. The author shares personal insights into GNOME's workarounds and the trade-offs between security and functionality in CI environments, suggesting future directions for development and the importance of ephemeral microVMs for maintaining security standards.