- Remove Boot=yes from workspace.nspawn configuration - Use machinectl shell directly without starting/booting container - Avoids "Failed to reset audit login UID" error in nested containers - machinectl shell works with non-booted containers via namespace entry