a5c6170ac020ffdfe55a3cedfd0b1beec2c28194
kanidm-unixd runs with DynamicUser=yes, so it cannot read the root-only /etc/kanidm/unixd_token. With service_account_token_path set in /etc/kanidm/unixd the daemon failed with PermissionDenied and no Kanidm user resolved. Drop that setting and inject the token with LoadCredential + KANIDM_SERVICE_ACCOUNT_TOKEN_PATH through a generated drop-in. Verified in a QEMU VM: kanidm-unixd active, 'kanidm-unix status' online, 'getent passwd job' resolves.
Description
No description provided
276 KiB