had to come back because there actually seems to be a project to build this:
https://github.com/darwin-containers
However it requires disabling SIP, so that's unfortunately a non-starter for anything serious today.