That will give you a read-only resinOS (based on Yocto. meta-resin layer). If you rpi is connected to the internet, you can use resin.io to remotely push application container updates and access the pi over a vpn.
https://docs.resin.io/learn/getting-started/raspberrypi3/nod...
Disclosure, I work at resin.io in the OS team on meta-resin.
The base resinOS is open source. And we are open-sourcing the rest of our stuff in due time as well.
http://layers.openembedded.org/layerindex/branch/master/laye...
Even without meta-debian, you can configure yocto to use the apt package management tools, and then you can point this at the relevant repositories. Read the manual for more information.
I did read about how to add APT by specifying: CORE_IMAGE_EXTRA_INSTALL += "apt" but how on earth does it know what you've 'baked' into your recipe? Otherwise surely it'd basically install the system again when handling the user's package's dependencies. Wouldn't it? Perhaps https://community.nxp.com/thread/325384#comment-486697 is the answer, which sounds like a bit of work.
I also found this which looks kind of interesting: https://elinux.org/images/c/c6/Smart_r002.pdf and https://community.nxp.com/docs/DOC-328199.
Users can apt-get all they want and it'll even be available next boot provided they shut down properly.
I have similar problem: we have consumer device on top of imx6. I used iMX6 SoloLite evaluation board kit (1GB of memory) with Fedora for arm as development prototype. For me, installing a package is not a problem at all: "dnf install package". I planed to use Raspbian or Fedberry on actual device, but our management blindly switched to Yocto, without comparing of alternatives. To install package on Yocto, we need to create our own recipe in our own layer,then rebuild Yocto, fix bugs and repeat, and then deliver update. We spent man-year to achieve same result as we already had with Fedora. We seriously lag behind schedule because two developers (and two consultants) are working on developing of our own custom OS instead of working on our application. Moreover, instead of single system for development/testing and production (Fedora or Debian on developer workstation, in Docker for CI, on actual device) we now have mix of two systems. I created configuration script with about fifty options to be able to compile for host and for Yocto at same time (including workaround for number of bugs in Yocto). Enormous development time was sink into ground because of this schizophrenia.
You could run Fedora in a container on your Yocto base using resinOS.
I wrote more about this in another comment. https://news.ycombinator.com/item?id=18093336