docker volume mounts preserve host permissions, and caddy container may run as different uid than host user, causing certificate read failures with restrictive (600) permissions.