Looked into Apples container framework first (for proper isolation) but switched to Docker sandboxes since they switched to mircoVMs too: https://docs.docker.com/ai/sandboxes/#why-use-docker-sandbox...
Quite similar to how Im using docker for a few years
https://github.com/jrz/container-shell
Quite similar to how Im using docker for a few years
https://github.com/jrz/container-shell