How to create a sandbox to run untrusted code/modules?

The only sure of way running untrusted code seems to be using docker.