Well, if you have BYOD policy consider yourself blessed. Many are simply not allowed to do whatever on their managed devices.
My recommendation is use OpenSSH (alternative: Wireguard, Tailscale for whole TCP/IP stack), tmux (or equivalent, there are alternatives such as zellij and rmux), and a keyboard (wired is more secure, YMMV). Then you have a thin client. Run Docker remotely, on a far more capable device than whatever your smartphone is. With Waydroid or another variant of remote Wayland you could even have the GUI part working.
I was able to do the above 5 years ago on Ubuntu and Arch. I am sure you can still do it nowadays.
One caveat. Don't do this in environments where you cannot auth in privacy. You must be able to trust your hardware, too. Don't bring this setup to e.g. China. You can put a strong password on your SSH private key, rotate it, and combine OTP/MFA.
Which leads me to say: I am puzzled how people can work in environments like coffeeshops, cafes, and I even see laptops used for work in swimming pool where I go weekly. Your screen can be viewed, recorded at all time, and I doubt the users are aware of that. Even passwords can be recorded.