While this would not answer your question, but according to podman maintainers, rootful podman with userns=auto
enjoys nearly as much security benefits as rootless. (As always, there are nuances to this)
Check out https://github.com/containers/podman/discussions/13728
Maybe you could consider running rootful podman, especially if the OS is immutable.
And I thought the year of linux desktop was coming…