I am not very experienced with the finer details of Singularity containers yet and I was wondering if an admin on a system can create Singularity containers which they can let ordinary users run, but preventing them from running with root privileges? Normal practice on our system is to let users build their own Singularity containers inside which they are the king of their own castle. Now I am investigating the possibility of offering some pre-defined Singularity containers which are configured by an admin and which the users are allowed to instantiate themselves, but where they cannot have root privileges inside.