Yes but NixOS does all of these things already, without the process overhead
Nix wraps your process in namespaces and seccomp?
Even the minimal SBOM part? It's hard to be more minimal than a busybox binary.
Nix wraps your process in namespaces and seccomp?