This serves to do two things:
1) chown /znc to znc:znc, which is really handy if the znc
user inside the docker container has a new uid, because the
files are stored on the host filesystem.
2) to drop privs to the znc user, to reduce the attack surface.