Explore how rootless Docker uses user namespaces, why kernel developers have concerns about the attack surface, and what unconfined flags really disable.