`docker = cgroups + namespaces` is a small lie.
Linux has a ton of different security primitives (including the LSM zoo), and each of them has various user-friendly frontends, with the more interesting ones (docker + other OCI-compatible stuff) composing multiple security features.