Related question: Which software do you recommend to sandbox a locally running AI agent, so that it can only access parts of the filesystem (e.g. one folder) and an allow-list of URLs?
Firejail if you want ease of use (there are a lot of ready profiles to be used).
Bubblewrap if you want more security, at the cost of having to do more manual work.
TL;DR Firejail is a blacklist of things, while bubblewrap is an whitelist, so bwrap policies tend to be tighter.
Do you fire up a docker image? Do you use virtualbox? ...