I think GAE isolation nowadays is done by gVisor[1]?
Looking at the doc [2] however, it seems like the old "proprietary" mechanism is still used for old (first generation) runtime. Probably this post is about that version.
[1] https://cloud.google.com/blog/products/containers-kubernetes/how-gvisor-protects-google-cloud-services-from-cve-2020-14386
[2] https://cloud.google.com/appengine/docs/standard/runtimes