/sys/fs/cgroup Namespaces: • Kernel-level resource virtualization and isolation • Mount, network, hostname, IPC, hostname, cgroups • Syscall-based interface - setns(), unshare(), clone() Mounts: • Resource gluing and isolation crossing • Bindmounts - generic path-to-path mounting • Overlayfs - stackable layers of filesystems Containers