Træfik backend for snapd

snapd-control grants device ownership to the snap for all systems it is installed on. This seems unreasonable considering what it is trying to do. -1 for use of this interface for the global store.

That said, perhaps an interface can be created for this where snapd can mediate the access itself by checking the security label of the connecting process and then checking to see if the interface is connected for this snap. Alternatively, a 3rd socket could be created by snapd for handling these sorts of requests. I suggest working with @pedronis, @niemeyer and @mvo (here in this topic) on how the design might look.