It seems binding to device would work on normal machines. It seems only systemd-nspawn has problem with that. Fix it by commenting out BintsTo= line on containers now (reported on rhbz#1941458).
Add dhcpcd user on installation, make local state directory writable by it.