Would rootless docker help? (Potentially even running that specific workflow with it's own dedicated user)