David Leadbeater
A deep dive into cgroups, unshare and other technologies in the Linux kernel used to create isolated containers (as used by Docker/lxc).