Destroying a network namespace destroys any virtual interfaces within it and moves any physical interfaces within it back to the initial network namespace
Linux Cgroup Namespace
rlimit limits resource usage such as CPU and memory of a collection of Process (进程). This prevents a single container from monopolising system resources, ensuring fair resource distribution among all containers