doc: clarify restrictions to run as non-root