Answer
runc reads the OCI spec, sets namespaces, configures cgroups, mounts rootfs using pivot_root, drops capabilities, and execve()s the entrypoint to create an isolated environment.
Sign in to access all features and personalize your learning experience.
Source: SugharaIQ