Does Kubernetes use chroot jails like Borg, or has it advanced to LXC containers? Nowadays LXC isolation seems strictly preferable.
From the paper: "We use a Linux chroot jail as the primary security isolation mechanism between multiple tasks on the same machine… all Borg tasks run inside a Linux cgroup-based resource container."
I think was in RHEL 6.2 possibly even 6.0
You may run O(10) containers on a single machine. When you run O(10k)+ containers in a cluster you need new tools to manage things.
Things can in fact work isolated without chroot, too. Its just convenient.