The oci-containers module has native rootless support via podman.user which handles cgroup delegation, runtime dirs, and cidfile paths. Delegate=true workaround for NixOS/nixpkgs#410857.