Best practices for apparmor and systemd-networkd for Debian sid container?

This seems to be an AppArmor issue. The issue mentions that lxc.apparmor.profile = unconfined is the only option here.

Note that this only affects lxc. The Debian images work fine in LXD.