VMs would cost 4x more. Kernel sharing is the economic moat.","Every container is just a process with blinders. Linux namespaces restrict what it can see — filesystem, network, process IDs. Cgroups limit how much CPU and memory it burns. No hypervisor, no