Just an update to my own feature request.
I'm currently up to version 8 to get this working, there are dependencies to newer versions of iptables as well as other kernel modules (most can be modules, others will have to be included in the kernel), I'm getting it to work. The size difference in kernel and image are very small. If I get this working I'll follow the guide to a create a pull request with all changes, the size diffs etc, then you can either accept or reject the PR. As it looks now, even though I have started a bit bigger project than I figured, it's relatively small changes to make this work and then we'll have much better capabilities to run Docker services on those boxes. I'll also have a look at the Docker add-on, which is running quite an old version of Docker, now that I'm into this stuff anyway.