First deploy failed: atrocore-db-init (User=postgres) could not read
/run/agenix/atrocore-env because agenix defaults to root:root:0400.
Follow the pg-cert/pg-key precedent: owner/group postgres, mode 0400.
Podman still reads the env-file and registry token as root (root
bypasses DAC), container pull/run unaffected. Agenix applies
ownership at activation time - no rekey needed. Validated on AZ-PRM-1.