I'm not suggesting containers but rather running binaries natively, just as separate users. No cgroups or overhead. Just normal binary access, just you won't have access to all files (and since everything is a file, "all files" includes hardware as well)
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments