Run the pi coding agent inside an isolated Docker container, one persistent container per workspace. A single bash script builds the image, manages per-workspace containers (with optional network isolation), bind-mounts config and sessions, and handles UID/GID mapping so files stay host-owned. All state lives on the host under ~/.pi/pipod/