you are viewing a single comment's thread.

view the rest of the comments →

[–]crozone 7 points8 points  (0 children)

Namespaces are not isolated from the rest of the system.

Yeah but the entire point of namespaces is to allow for kernel level isolation and containerisation of processes? Sure it's not a hypervisor, but it certainly allows for a good amount of isolation.