I'm working on a project that solves some of this [1]. It runs agents in Docker and proxies the ACP connection via websocket, with WASM-based plugins in that proxy so you can get in between your client and the agent if you want.
It currently tears down the container after the session, but it wouldn't take much to leave it running post-connection and make a mode that continually re-uses the same container.
It's also possible to intercept ACP read/write file and shell commands via one of the WASM-based plugins if you wanted to execute them in a separate VM/container. I'd have to double check on FS permissions for the Docker socket; I think plugins have no file access currently because I haven't figured out a permission system for it yet. The whole plugin system is new and I'm still working out some of the edges.
Feedback and feature requests welcome!