The upstream repository now includes chronyd-restricted.service, which starts chronyd without root and can be used with minimal NTP/NTS configurations. It will be included in our package, but probably not enabled by default as that would break more advanced configurations. I also looked into a possibility of using a generator to switch between these two or possibly more different services according to the chrony configuration, but there seems to be a major usability issue that the generators run only on boot and systemctl daemon-reload, which would cause problems when the configuration is modified and the service restarted restarted without reboot or the systemd reload.
This issue will be fixed with rebase to chrony-4.4 (bug #2231078), which will add the chronyd-restricted service as an alternative to the less restricted chronyd.service.