Using QEMU to produce Debian filesystems for multiple architectures
headmelted.com
headmelted.com
I hit the same roadblock with qemu-debootstrap, which is a great wrapper for this use case, but makes (to be fair, reasonable) assumptions about permissions you do and do not have that might not apply in a build agent where you don't have control of the kernel.
Separating the process out into two stages helped with this as I was manually able to perform only the mounts needed to get a minimal filesystem produced.
Not to plug but I wrote another article that explains the context in which I'm producing the builds and goes into more details about the constraints (https://headmelted.com/continuous-delivery-with-azure-pipeli...).
All that said, debos is a great tool if it fits your situation (as is qemu-debootstrap!)
https://wiki.debian.org/Multistrap
You still need either an embedded system or a QEMU emulator to finish installing the packages but you can build a complete root filesystem with a simple configuration file.
If it helps with piece of mind, the images are built in the open (the Azure Pipelines YAML file in the repo handles this).
There are a bunch of scenarios in which you may find yourself unable to create these with debootstrap yourself (e.g. restricted permissions, a kernel without binfmt_misc suppport), but are able to use them (using proot to avoid needing admin, or Resin's patched version of QEMU that reworks execve() to operate without binfmt)