They do get applied but htop inside the container is still able to see all the system resources but will not be able to use them:   For example if you install something like stress and then stress the CPU, with more than two cores you will see that it only uses cores 0-1 on my system: I hope you see that I got two terminal windows, the window in the background is from the container where I started a stress test with 12 cores and the htop terminal window is also f