Use when development containers must run non-root while bind-mounted source, named volumes, tmpfs outputs, and generated files remain writable without polluting or taking ownership of the host checkout.