1b21f001eb
supervisord runs as root inside the container but cap_drop: ALL still blocked it from signaling opendkim (a different uid) — cross-uid kill() checks CAP_KILL regardless of the caller's uid. Domain add was failing in prod with "unknown problem sending sig opendkim ... PermissionError: Operation not permitted".