by: sjdonado
The Linux kernel's support for namespaces mostly [1]
Isolates an application's view of the operating environment
cgroups provide resource isolation, including the CPU, memory, block I/O and network.
The Remote - Containers extension lets you run Visual Studio Code inside a Docker container.