I try to avoid setuid binaries written in memory-unsafe languages.

This feels like the wrong direction.

Looks like there is youki [1] for that.

[1] https://github.com/containers/youki