In a container context to be properly abstracted from what is outside the container you need fresh mounts for the controllers you are going to use and the ability to have a different binding of control groups to hierarchies.
In fairness Paul Menage has been looking at this a bit after I raised the issue with him at plumers conf.
James seems a little more dense and seems to not have understood when I pointed out that control groups and namespaces were not them same thing. I guess more repetition of the obvious is in order.