You almost certainly don't desire to setup linux namespaces, cgroups and every little thing else from scratch For each and every new container you need to make. The tool that does it to suit your needs is called the "container runtime" - the minimal, even the lowest level utility of https://bibisoutherncontainers.com/