> That's why it's gated in most distros by default.
Debian used to gate them behind a sysctl, but that's changing in the upcoming Bullseye release:
"The previous Debian default was to restrict this feature to processes running as root, because it exposed more security issues in the kernel. However, as the implementation of this feature has matured, we are now confident that the risk of enabling it is outweighed by the security benefits it provides."
https://www.debian.org/releases/bullseye/amd64/release-notes...
Ubuntu has allowed user namespaces by default for years. Which distros are still holding out?