root의 file system을 새로 만들어서 탈옥 못하게 함
pivot_root [new-root] [old-root]
cd /tmp mkdir nginx-root docker export $(docker create nginx) | tar -C nginx-root -xvf - mkdir new-root mount -n -t tmpfs -o size=800M none ./new-root cp -r nginx-root/* ./new-root mkdir ./new-root/old-root cd new_root unshare -m pivot_root . old-root cd / ls