BindReadOnlyPaths
This should fix temporary name resolution errors observed in erpnext.
Minor cleanup and explanatory comment for confinement.packages
We don't use pkgs from path, but prefer explicitly referring to pkgs
When started before erpnext-web, the scheduler and queues do not start
successfully, because the common_site_config.json is still missing.
We can not schedule or queue anything yet, so starting after erpnext-web
is fine.
This fixes deployment via deploy-rs