You can create a Dockerfile with all your standard tooling in it (compilers, interpreters, build systems, etc.) as well as your harnesses like Opencode. Then -v your workspace and ~/.config/opencode. Create a user in the Dockerfile and have it run as that user instead of root. You can give it your UID so it can read/write to the workspace in the volume mount.
You can set the entrypoint to your harness (e.g. opencode). Alternatively you can set the entrypoint to something like cat or sleep, then just exec into the running container to start the harness or whatever other tools you want.
I’ve been meaning to do this myself. I do tend to run Opencode and Claude Code just as my regular user and it’s starting to worry me too.