Package applications with OCI images and run them using isolated processes, namespaces, and resource limits. Create secure, reproducible container builds and runtime configurations.