I think I and lot of others lack a clear instruction how to use it and what are the limitations. With docker/containers we are sold the promise of sandbox (not true, but regardless), and with existing systemd user level separation is really hard to grasp.
it has all the options you would ever want, and is actually deeply aware of the kernel capabilities.
every day someone comes with a new sandbox solution because they are too lazy to read one page documentation.