Can I just use Docker for this?
Container namespaces are a weaker boundary than a microVM, and kernel escapes are a real category of vulnerability. For code an LLM wrote, use hardware-level isolation. You'd also be building the sub-second start machinery yourself, which is not a weekend project.