Look at
https://nodered.org/ , many people use it for automating stuff.
The DIY version:
I'm sure there are better ways, but that's how I would do it:
> how can I check the repository size?
[1] https://stackoverflow.com/questions/8185276/find-size-of-git...
> cloning a couple of repositories at the same time might make the server slow
long running operations must run asynchronously. I would implement that as: client sends HTTP request to the server, server responds with a job ID and creates a temp directory with a random name containing information about the job (eg parameters). A scheduler (cron?) picks up the job, changes status, executes it. The scheduler can decide on parallelisation. The scheduler must run as a low-privileged user, possibly in a container as you suggested. The client needs to poll the server for job status.
> running shell commands on the actual system might be dangerous
The method described earlier partly mitigates that as the process doesn't run in the web server. I would create special job types (eg. one shell script for checking out, one for committing, one for pushing etc) and sanitise arguments (eg. no weird characters allowed). Running each job run in a sub directory of its own limits spill-over.