5️⃣0️⃣ Here's the 50th post highlighting key new features of the upcoming v258 release of systemd. #systemd258
User namespaces are weird beasts: on one hand they are supposed to be something that you can acquire without privileges, but on the other hand if you want more than a single UID mapped into them, you need multiple UIDs, and that's a resource you cannot acquire without privs.
To deal with that multiple systems have been devised.