First deploy failed: atrocore-db-init (User=postgres) could not read /run/agenix/atrocore-env because agenix defaults to root:root:0400. Follow the pg-cert/pg-key precedent: owner/group postgres, mode 0400. Podman still reads the env-file and registry token as root (root bypasses DAC), container pull/run unaffected. Agenix applies ownership at activation time - no rekey needed. Validated on AZ-PRM-1.