Docker orchestration for running third party containers in a zero trust network

I am prototyping a SaaS solution where users are able to upload and run their containers in our cloud, and connect them to our API and services. Each user must be able to run their containers in an isolated, zero-trust network.

What are some good tools for zero trust container orchestration?

I mainly used AWS ECS / Fargate in production before, and obviously they do not work for multiple reasons. For example, ECS provides each task access to host metadata API, which basically breaks any isolation.

Author: loki198978