Firejail is probably what you want. I'd be wary of considering Docker as a jail - it does some isolation, but I've yet to see any serious effort or analysis of "safely run arbitrary code as root in docker and avoid escape" (the scenario being at least a full compromise of the app, with potentially an elevation to root in the container). Docker is "(shipping) container first" not "(CIA black site) container first".
Firejail isn't perfect - but it's at least designed to be a jail/sandbox.
There's also the possibility to use lxc via lxd - if you're running xorg you can forward x11 over ssh to the container (or vm). However access to xorg is problematic (eg shared clipboard, window/screen access).
Wayland supposedly does "everything x does" - but I don't know how you connect displays via the network.
But in the end (even though you requested "not vm") - I'd probably have a look at qubes os: https://www.qubes-os.org/
Afaik it mitigates the "shared xorg server" via using x-in-x nested servers (eg xephyr).
Also came across this, which appears to be a little better than "just" docker - but I'd probably still go with firejail or qubes os:
https://github.com/mviereck/x11docker/blob/master/README.md