Great so you made capisicum with docker .
https://www.cl.cam.ac.uk/research/security/capsicum/
Docker docker docker docker
https://www.cl.cam.ac.uk/research/security/capsicum/
Docker docker docker docker
Your approach has the problem of needing the inherent insecurities of docker. Because everything within docker has to be managed either by root or someone within the docker group, you have a greater surface area exposed where if an malicious app is able to get hold of the docker socket file, it now owns your system. A capability-based security system, on the other hand, wouldn't be able to touch the docker socket, even if it was run as root.