Created attachment 460774 [details] knot.service Force user and group in systemd service. Do not wait for privileges drop.
The systemd feature AmbientCapabilities is only available since 229 release. As the current stable systemd for Gentoo is 226, I think we have to wait before integrate your service file.
As current stable systemd is >=233 for all arch, your service file has been added to the tree, as of net-dns/knot-2.5.3-r1. See: https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=91cdae70f2fa6322ff9b38336b24312bdd3c3810