- AppBox is not sandbox, it.s for all kinds of network applications
- AppBox don't isolate file system, only isolate applications or application groups
- AppBox is to avoid docker's rich functions
- Leverage network name space mainly to isolate subnet for applications with an OS
- Linux tool 'ip'