Deep dive into runc and OCI specifications
mkdev.me
mkdev.me
Bocker (docker runtime in ~100 lines of bash) does a good job showing what's really happening. Basically namespaces and cgroups, both of which come with Linux. The source is probably the best "deep dive" on containers I've found.
https://github.com/p8952/bocker
Docker thrives because of the repository of images, a great name, and some marketing. Runc thrives because it provides a nice wrapper around namespaces, mounts, cgroups, virtual network interfaces, etc. Neither really provides the magic, though...it's already there.
gvisor is an example that runs containers via runc without all that, using the same scheme as User Mode Linux instead.
(it's mentioned way down near the end of the article, and looks like it is less resource-intensive)