I‘m using https://www.docker.com/products/docker-sandboxes/

Better isolation than running it in a container.