I also experience with Secureblue, so here are my answers:
- I used GNOME because it is the only DE that protects the screen copy API. I used GNOME extensions because native methods of customizing UI/UX are very limited.
- I personally re-enabl Xwayland because many apps (eg Steam) still use/require XOrg.
- Yes I recommend use and recommend Bubblejail as a simple way of sandboxing some apps. Not a “super tight” but much better than unsandboxed. FYI, AppImages don’t work with Bubblejail, or Secureblue (cus they remove the unmaintained FUSE dependency).
Are you on the userns image? Because podman/docker/toolbox/distrobox all require unprivileged user namespaces.