Keeping out the `/dev/` tree is done when tarring things up so that the `bootstrap.sh` script will have access to devices at run-time. This approach also protects against removing devices that have been mounted into the chroot, if any (e.g. devpts).