When running in podman rootless container launched with --userns=keep-id alone, bwrap refuses to run with following message:
bwrap: Unexpected capabilities but not setuid, old file caps config?
However, adding --user 1000:1000 (or any other uid:gid) makes bwrap work as expected.