So does this mean you can run containers in containers orchestrating other containers.
Containers must really be the holy grail of serverless and cloud "nativeness".
So, namespaces are task level things in the kernel. (Every thread is a task, and by default every process has one thread, so every process is also at least one task.)
https://elixir.bootlin.com/linux/latest/source/include/linux... (That's where the task_struct starts and it has an nsproxy member.)