Just found it: systemd comes with a cool replacement for `chroot(1)` (on Ubuntu it's a separate package `systemd-container`) which not only virtualizes the filesystem root but actually wraps the process in a lightweight container.
Fast, secure and up-to-date instance. PrivacyTools provides knowledge and tools to protect your privacy against global mass surveillance. Website: privacytools.io Matrix Chat: chat.privacytools.io Support us on OpenCollective, many contributions are tax deductible!