What kind of annoying things are you dealing with?
Troubleshooting with a machinectl session, switching between services, backing up… It is small annoyances but if I can avoid them i’d like it.
You don’t have to put the user home in /var/lib either if that helps at all.
I half regret doing it.
If you’re already running rootless, I’d keep doing that unless there’s a really good reason not to.
The plan is about switching to a single user, I will stick to rootless podman this is for sure. It is more about dedicated users or a single one.
sugar_in_your_tea@sh.itjust.works 22 hours ago
You shouldn’t have any user home for your services, you shouldn’t even allow them to login at all. They should only have group access to resources they need, and containers should restrict what directories they have access to.