Frankly, ssh-to-container is a "slaps forehead" obvious solution and I'm surprised none of us thought of it before - I'd love to see it as a standard option in the OS, e.g. chsh allows you to specify a container and optional port and volume mappings.
In the old days, we'd (try to) use chroot, but that has all sorts of big problems with needing access to various directories, and those batches begat patches...
I think CNCF is at the point where you can assume that "there's a CNCF project for that" is true for anything container/kubernetes related.
Also, containers mean that one user can make changes (install/upgrade software, etc) and not adversely affect another user (incl their security stance).
loginctl enable-linger USER
(run once, as root) should cause USER's podmansh container to start as soon as the system enters multi-user mode, independent of USER's login sessions, allowing persistent daemons, including those necessary for job scheduling, namely…Ordinarily, users can create systemd timer units[4] to schedule at- and cron-style jobs; I assume you need to run a systemd instance inside each user's podmansh container to allow users to create systemd units in the present containerized context (running systemd inside a container is explicitly supported by podman[5]).
If your users don't like systemd, you can also run traditional atd/crond daemons in user containers.
[1] https://www.freedesktop.org/software/systemd/man/systemd.gen...
(This is the same mechanism that, e.g., automatically creates systemd mount units for mounts defined in /etc/fstab.)
[2] https://docs.podman.io/en/latest/markdown/podman-systemd.uni...
[3] https://github.com/containers/podman/blob/6ab38e55e733e70c95...
[4] https://www.freedesktop.org/software/systemd/man/systemd.tim...
[5] https://docs.podman.io/en/latest/markdown/podman-run.1.html#...
sudo systemctl edit --force user-1234.slice
[Slice]
MemoryMax=1G
CPUQuota=10%
It's also something that's been available on the other UNIX-likes (FreeBSD/Solaris) since essentially forever.