Over in BZ#1510139, it was reported that we were unable to to run systemd in a non-privileged container. After some trial and error, it was discovered that in order to get the container running we had to enable the 'container_manage_cgroup' boolean. Dan suggests we modify the SELinux policy to have this boolean enabled in comment #9 of the above mentioned bug. We were seeing these issues using the following version of 'selinux-policy': selinux-policy-3.13.1-283.16.fc27.noarch
*** This bug has been marked as a duplicate of bug 1510139 ***