lxc: Drop a bunch of capabilities in the template container
drwxr-xr-x - etc
drwxr-xr-x - usr
drwxr-xr-x - var