Module 3.11 — Process isolation, cgroups, overlay filesystems
Process ID isolation. PID 1 inside = different PID on host.
See how each namespace type isolates container from host.