This is the first step for unprivileged nixos containers support. Fixes #30019. See also #18825, #57083, and #67130.