Apparmor blocks systemd services in container

One potential fix we’re considering is shipping a file in LXD images which disables those systemd features for the entire container. It’s not yet clear how viable that is and what that may break though.