- Bind calibre-sa to anyuid SecurityContextConstraints - Enables secure non-root execution for LinuxServer containers - Maintains production security while ensuring container compatibility - Fixes supplementary group issues with s6-overlay