> They claim that "standard containers" cannot run a full OS. ... this works just fine with rootless podman and, more recently, rootless docker.
> Anyone who wants unprivileged system containers might want to look into rootless docker or podman rather than this.
Perhaps I'm missing something, but I have been running full OS userlands using "standard containers" in production for years, via LXD[1].