I like the idea. For lack of a better name, let's call this "lock/unlock" app containers.
Container starts locked. When unlocked:
It will make the container rw Disables automatic updates Gives warning to user that all changes will be lost when updating and are not part of any backups Automatically starts up the container (unlike debug mode which keeps the container in paused mode).I think this gives the customer a window to "hotfix" things until upstream (or packaging team) figures out some fix.