Summary of the above:
- Will need a systemd unit to run docker-registry.wikimedia.org/repos/releng/zuul/zuul/zuul-executor:wmf-12.0.0-5 in privileged mode
- The running container will need a bind mount with an ssh key allowing the zuul user to access the nodepool node
- Needs to allow connections from the zuul-web/fingergateway node on port 7900
- Will need a bind mount to /var/lib/zuul on the host. This will be a large, active volume, equivalent to /srv/zuul/git on the contint hosts.