It works in app vm with no problem.
You install it to template.
You make bind-dir to /opt/safing/portmaster in app vm, run it once in app vm and make some config changes for config file to be saved. Then copy it from app vm to template. After that bind-dirs start to work.
Shut down template and restart app vm.