I don't see anything in the code which sets/handles the current uid/gid - how do you prevent every file created by a dockerized wrapped app being owned by root?
Would this be easy to fix? Like, determining the current user id, and setting it when launching the command? Or would the host uid need to be mapped to the docker uid, which might be different for each image?