Firejail seems like the right tool for a somewhat complicated desktop application that you want isolation for, that's not simple to containerize.