also, raise limits to ensure reasonable startup time, now that StartLimits are actually enforced
also, nixos/containerd: module init