For anyone who cares about resource control setting up the memory control group in combination with user namespaces is strongly recommended. User namespaces are a particular problem when it comes to resource control. Not all of the resources you can create with a user namespace currently have ordinary resource limits. When you can switch uids the ordinary resource limits don't mean much. The memory control group is capable of limiting all of those things today. So if you care about keeping rude users of your system under control and you enable user namespaces setting up memory control groups is to limit them is strongly recommended. Eric _______________________________________________ Containers mailing list Containers@xxxxxxxxxxxxxxxxxxxxxxxxxx https://lists.linuxfoundation.org/mailman/listinfo/containers