You almost certainly don't want to set up linux namespaces, cgroups and every little thing else from scratch For each and every new container you would like to create. The Instrument that will it to suit your needs is called the "container runtime" - the reduced, even the lowest level utility of each container setting.Isolated storage is for apps w