There's no need to bind mount the full /etc/pki from the host. This file can be generated from /usr.
Run all programs in the build root through osbuild-run. The things it sets up are probbaly needed by everything.