Using the lxc.mount.entry method in unpriveldged containers, do you still need to do the gui/uid remapping?
Here's a snippet of my container.conf. IIRC, i needed to pass gui/uid of 864 and 865 to get permissions to work correctly.
mp0: /mnt/pve/nas1-scratch,mp=/mnt/scratch
mp1...