The role services are implemented as individual docker containers - for example the web server (Apache, LiteSpeed, OLS), Dovecot IMAP, Postfix, rspamd, etc. These containers are shared between the websites provisioned to hat server.
Website applications (currently PHP + any cron jobs, SSH sessions, etc) use Enhance's own containerisation engine using kernel namespaces and cgroups. These are individual per-website containers which ensures each website is isolated even within a single customer subscription.
Any overhead from the containerisation is negligible.