nss/pam consumers (sshd, the display manager, systemd-userdbd, polkit, ...) were denied write access to /run/kanidm-unixd/* (var_run_t), so Kanidm users could not be resolved or authenticated and logins failed with 'invalid user'. Add the audit2allow-derived CIL and load it at build time (semodule noreload).