In a way, but chroot only isolates file systems (process only has access to an isolated “root” which isn’t the actual host’s root). Rootless Podman/Docker goes a few steps beyond and utilizes cgroups, and user namespaces to isolate not only file systems, but also processes and networking.