Update on 2020-02-23
Turns out this doesn't work at all, all the time.
Some notes for myself regarding molecule testing
I recently removed my everyday user from the docker group, so programs running under my user can't run arbitrary docker commands anymore. Wooho.
Sudo with docker instead
The original post I had here wasn't working after all, so I decided to remove it.
I don't know how I got it to work.