That's an interesting idea about using a unified network interface. Do you know how you might then get the right packets to the right containers/processes? Does that even matter with Wireguard?
Example vpn container:
docker run --name foo --cap-add=NET_ADMIN ...
Other container: docker run --net=container:foo ...
Now you'd need to specify the respective routing rules [1] in the container.[1] i.e. https://github.com/bubuntux/nordvpn/blob/master/start_vpn.sh...