Does this require your Python app to run on a user in the docker group, thus giving your app Sudo privilege?
1 The container would need to be privileged so that it could run a docker daemon and containers (sidomo processes) within itself.
2 (the "right" way) Use the host's docker daemon from within the first container by binding the docker.sock to the child container. The first container can start and stop others that run next to it, instead of inside it. This way there's no recursion, and no containers need root privileges.