fun fact: you can already have almost everything except /var/ and /home/ read-only (there are still some legacy problems in /etc/, namely passwd, shadow, group... that I think userdbd can handle, but are there because of backwards compat). You can add to /etc/ by using systemd-confexts and overlaying files onto there (and systemd-sysext for /usr/). ~~Tho you have to choose the software you run somewhat carefully~~ Lets rather say, the infrastructure is already mostly there for this to be possible.
I'd love to have a way to have root really only be a read-only tmpfs that is only used for mount points (specifically /usr/, /var/ and /home/) and symlinks (for example /var/home/ to /home/ if no separate partition is wanted).