kernel.unprivileged_userns_clone=0
because it breaks too much fixes https://github.com/Kicksecure/security-misc/issues/274
panic_on_warn=1