But what is wrong with docker or a regular VM?
ie. "run foo.exe with max 500mb ram and it can only exist/touch files in /bar"