If iptables.service does not set After=local-fs.target, systemd will start it before /var is mounted, which results in: iptables-restore[1210]: Can't open /var/lib/iptables/rules-save: No such file or directory
I've been told that systemd-units shall be nuked and services be moved to the actual packages. Hence the bug title should probably refer to the actual package, too.
I just fixed it in the overlay for now. Thanks for reporting.