You might want to check debos [1], which I think allows something similar.
I hit the same roadblock with qemu-debootstrap, which is a great wrapper for this use case, but makes (to be fair, reasonable) assumptions about permissions you do and do not have that might not apply in a build agent where you don't have control of the kernel.
Separating the process out into two stages helped with this as I was manually able to perform only the mounts needed to get a minimal filesystem produced.
Not to plug but I wrote another article that explains the context in which I'm producing the builds and goes into more details about the constraints (https://headmelted.com/continuous-delivery-with-azure-pipeli...).
All that said, debos is a great tool if it fits your situation (as is qemu-debootstrap!)