The decision to drop stderr has made my life hell. I wish systemd guys understood how important it is to those of us that run servers.
Maybe I'm missing the point here, but there has not been any "decision to drop stderr". It's clearly possible to set where it should go:
Controls where file descriptor 2 (STDERR) of the executed processes is connected to. The available options are identical to those of StandardOutput=, with one exception: if set to inherit the file descriptor used for standard output is duplicated for standard error. This setting defaults to the value set with DefaultStandardError= in systemd-system.conf(5), which defaults to inherit.
that hasn't worked with GNU rm in a long time, sudo or not.
So, rm -rf