We should leave a notice in the README about Debian hardening regarding userns.
To enable, we need to:
echo 1 > /proc/sys/kernel/unprivileged_userns_clone
and make it persistant using:
echo 'kernel.unprivileged_userns_clone=1' > /etc/sysctl.d/userns.conf
I'm also reading a similar path is available for newer kernel with a different switch.