The system container is a resource-only container which contains all non-kernel processes that are not already part of a container. This will allow monitoring of their resource usage and limiting it (eventually).
Implementation maintains a thread which ensures that the Docker daemon is in a container.