Answering to myself: it turned out that this is not something that you can do as a
non-root user. The solution is to leave out the /sys/fs/cgroup volume altogether.
The Molecule documentation (which I based my example on) has been updated to take this
into account:
https://github.com/ansible/molecule/pull/2358
Bottom line: not a Podman problem per se.
Best regards,
Per