I've been successful with getting incus running with this for sandboxing the opencode session. I plan on writing a blog post on it.
This might interest you (disclaimer my project. Well mostly Opus')
https://github.com/jgbrwn/vibebin
This might interest you (disclaimer my project. Well mostly Opus')
https://github.com/jgbrwn/vibebin