A PID namespace numbers processes from 1 again. Its PID 1 acts as init: when it exits, the kernel kills the rest of the namespace, and signals it has no handler for are ignored, so a server that does not handle SIGTERM is only stopped by SIGKILL after Docker 514 's 10-second grace period (BookNest Dockerfile). A mount namespace gives the process its own mount table. unshare from util-linux creates both without Docker:
sudo unshare --pid --fork --mount-proc ps -ef
sudo findmnt -N "$PID" -o TARGET,FSTYPE | head -5Output
UID PID PPID C STIME TTY TIME CMD root 1 0 0 16:08 pts/3 00:00:00 ps -ef TARGET FSTYPE / overlay ├─/proc proc │ ├─/proc/bus proc │ ├─/proc/fs proc
With --fork, ps is the first process in the new PID namespace and sees only itself; --mount-proc mounts a fresh /proc so it reads the new numbering. findmnt -N reads the container's mount table: an overlay root (Overlay Filesystems), with parts of /proc re-mounted read-only to hide host details.