If you wanna NIH you can just build your own docker. It's just an abstraction around some newer syscalls for process isolation. There's really not much magic to be found if you look into how it's done.
You can probably have a working prototype up in a weekend if you've got some systems programming experience.